A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/faq/3562/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-08 19:20
Updated : 2026-09-10 04:18
NVD link : CVE-2026-85384
Mitre link : CVE-2026-85384
CVE.ORG link : CVE-2026-85384
JSON object : View
Products Affected
No product.
CWE
CWE-121
Stack-based Buffer Overflow
