CVE-2026-85384
nicheStack Buffer Overflow in TP-Link RE210 AC750 Extender Allows Authenticated RCE
CVE-2026-85384 is a stack-based buffer overflow (CWE-121) in the httpd component of the RE210 AC750 Wi-Fi range extender, caused by improper bounds checking in the splitString function when parsing an uploaded configuration file. An attacker who is already authenticated to the device's management interface and is on the local (adjacent) network can upload a specially crafted configuration file to trigger the overflow and execute arbitrary code on the device. Successful exploitation could expose sensitive information, alter the device's configuration and network behavior, or render the device unavailable. Only deployments of the affected RE210 AC750 extender are impacted, and the attack requires local network access plus valid credentials. As of this writing there are no known public exploits, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Check the vendor's advisory for this CVE and upgrade RE210 AC750 firmware to the fixed release once published, since specific patched version numbers are not included in the current data. Until then, limit web management access to trusted LAN clients, change default management credentials, and avoid uploading configuration files from untrusted sources. Monitor the device for unexpected reboots or configuration changes as a sign of exploitation attempts.
| TP-Link RE210 AC750 Wi-Fi Range Extender (httpd component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
- Weakness
- CWE-121
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.