A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
History

Thu, 10 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
Title Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published: 2026-09-08T18:43:58.166Z

Updated: 2026-09-10T03:57:38.353Z

Reserved: 2026-09-03T18:02:10.505Z

Link: CVE-2026-85384

cve-icon Vulnrichment

Updated: 2026-09-09T20:38:27.590Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T19:20:07.763

Modified: 2026-09-10T04:18:18.530

Link: CVE-2026-85384

cve-icon Redhat

No data.