Description
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.





Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
Published: 2026-09-08
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The RE210 AC750 router contains a stack‑based buffer overflow in the httpd component’s splitString function. The overflow is triggered when an authenticated local attacker uploads a crafted configuration file, allowing arbitrary code to execute on the device. Once exploited, an attacker can read or modify sensitive device credentials, alter network routing or firewall rules, or render the router inoperable.

Affected Systems

This flaw is present in TP‑Link Systems Inc.’s RE210 AC750 router. No version‑level details are provided, so all firmware releases that include the vulnerable httpd module are potentially affected.

Risk and Exploitability

With a CVSS score of 8.5 the vulnerability is considered high severity. Although no EPSS score is published and it is not listed in the CISA KEV catalog, the exploit requires only local network authentication, a realistic scenario in many up‑and‑running environments. Successful exploitation compromises the confidentiality, integrity, and availability of the device and the networks it connects.

Generated by OpenCVE AI on September 9, 2026 at 13:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TP‑Link that patches the vulnerable httpd component
  • Restrict local network access to the router’s web management interface to trusted administrators only
  • Monitor device logs for anomalous configuration‑upload attempts and validate file content before processing

Generated by OpenCVE AI on September 9, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link Systems Inc.
Tp-link Systems Inc. re210 Ac750
Vendors & Products Tp-link Systems Inc.
Tp-link Systems Inc. re210 Ac750

Thu, 10 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
Title Authenticated Stack-Based Buffer Overflow in RE210 AC750 Configuration Import
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Systems Inc. Re210 Ac750
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-09-10T03:57:38.353Z

Reserved: 2026-09-03T18:02:10.505Z

Link: CVE-2026-85384

cve-icon Vulnrichment

Updated: 2026-09-09T20:38:27.590Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T19:20:07.763

Modified: 2026-09-10T04:18:18.530

Link: CVE-2026-85384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:39Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow