Impact
The RE210 AC750 router contains a stack‑based buffer overflow in the httpd component’s splitString function. The overflow is triggered when an authenticated local attacker uploads a crafted configuration file, allowing arbitrary code to execute on the device. Once exploited, an attacker can read or modify sensitive device credentials, alter network routing or firewall rules, or render the router inoperable.
Affected Systems
This flaw is present in TP‑Link Systems Inc.’s RE210 AC750 router. No version‑level details are provided, so all firmware releases that include the vulnerable httpd module are potentially affected.
Risk and Exploitability
With a CVSS score of 8.5 the vulnerability is considered high severity. Although no EPSS score is published and it is not listed in the CISA KEV catalog, the exploit requires only local network authentication, a realistic scenario in many up‑and‑running environments. Successful exploitation compromises the confidentiality, integrity, and availability of the device and the networks it connects.
OpenCVE Enrichment