ZeroHour

CVE-2026-85384

niche

Stack Buffer Overflow in TP-Link RE210 AC750 Extender Allows Authenticated RCE

CVSS 4.0
8.5 high
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-85384 is a stack-based buffer overflow (CWE-121) in the httpd component of the RE210 AC750 Wi-Fi range extender, caused by improper bounds checking in the splitString function when parsing an uploaded configuration file. An attacker who is already authenticated to the device's management interface and is on the local (adjacent) network can upload a specially crafted configuration file to trigger the overflow and execute arbitrary code on the device. Successful exploitation could expose sensitive information, alter the device's configuration and network behavior, or render the device unavailable. Only deployments of the affected RE210 AC750 extender are impacted, and the attack requires local network access plus valid credentials. As of this writing there are no known public exploits, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Check the vendor's advisory for this CVE and upgrade RE210 AC750 firmware to the fixed release once published, since specific patched version numbers are not included in the current data. Until then, limit web management access to trusted LAN clients, change default management credentials, and avoid uploading configuration files from untrusted sources. Monitor the device for unexpected reboots or configuration changes as a sign of exploitation attempts.

Affected
TP-Link RE210 AC750 Wi-Fi Range Extender (httpd component)
Estimated exposure
nicheLikely on the order of tens of thousands of devices worldwide (single legacy consumer extender model; no public install-base or scan data available) — The flaw affects one specific, older consumer range-extender model rather than a broad product line or cloud service, and exploitation requires local network access with valid credentials, so the plausible affected population is limited to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.

Weakness
CWE-121
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.