CVE-2024-25139

CRITICAL

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve c...

Affects 2 products across 1 vendor.

BCS6.74
CVSS 3.110.0
EPSS0.9%
Percentile56th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-120: Buffer Copy without Checking Size (Classic Buffer Overflow)

Program copies data to a buffer without verifying the source data fits within the destination.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-120
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-120
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-120
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-120
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-120
Show all 13

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability exists in TP-Link Omada er605 versions 1.0.1 through 2.2.3, where an integer overflow in the cloud-brd binary leads to a heap-based buffer overflow, potentially allowing an attacker to execute arbitrary code with root privileges.

BSID: BS-2024-GLOBAL-051275-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-25139?
A critical vulnerability exists in TP-Link Omada er605 versions 1.0.1 through 2.2.3, where an integer overflow in the cloud-brd binary leads to a heap-based buffer overflow, potentially allowing an attacker to execute arbitrary code with root privileges.
What is the CVSS score for CVE-2024-25139?
CVE-2024-25139 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.9%.
Is CVE-2024-25139 actively exploited?
No confirmed active exploitation of CVE-2024-25139 as of 2026-05-30.
How do I remediate CVE-2024-25139?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-25139?
CVE-2024-25139 affects: Tp-Link, Tp-Link.
Vulnerability Details
CVE IDCVE-2024-25139
BSIDBS-2024-GLOBAL-051275-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2024-03-14
Last Modified2025-09-18
ICS Relevance90%
Weakness (CWE)
SourceNVD
Official Description

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level. This is fixed in ER605(UN)_v2_2.2.4 Build 020240119.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is triggered by an integer overflow in the cloud-brd binary, which can be exploited to cause a heap-based buffer overflow. This overflow can be shaped to execute arbitrary code in the context of the cloud-brd binary, which runs with root privileges.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Tp-Link Omada Er605 Firmware
Tp-Link Omada Er605
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 875 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashec246784edc8d0a5d1655a90a744efad129f5f984693d10b863e96fe2947332fc1bd01fea385db57e64f8eb60bfa259d9efe5231ae63875b80f6f4919465250b
Related CVEs affecting Tp-Link
CVE-2013-2578 10.0 cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC317... CVE-2013-2579 10.0 TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly... CVE-2023-36355 9.9 TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipSt... CVE-2017-8220 9.9 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 R... CVE-2023-31710 9.8 TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build...
View all Tp-Link CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →