CVE-2022-48194: TP-Link Tl-WR902AC Firmware

High severity, CVSS 8.8. EPSS: 33.5% chance of exploitation in the next 30 days.

TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

Affected products

  • TP-Link Tl-WR902AC Firmware: up to and including 3.0.9.1

Published 2022-12-30. Last modified 2026-06-17.