CVE-2026-85384 PUBLISHED

Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import

Assigner: TPLink
Reserved: 03.09.2026 Published: 08.09.2026 Updated: 08.09.2026

A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.

Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor TP-Link Systems Inc.
Product RE210 AC750
Versions Default: unaffected
  • affected from 0 to 3.14.2 Build 141218 Rel.36430n (EU) (incl.)
  • affected from 0 to 3.14.2 Build 171205 Rel.71984n (US) (incl.)

Credits

  • Michael Ace Bengil (Archan6el) finder

References

Problem Types

  • CWE-121 Stack-based buffer overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers