Buffer Overflow Vulnerability in TP-Link AX1800 WiFi 6 Router
CVE-2023-28760
7.5HIGH
What is CVE-2023-28760?
The TP-Link AX1800 WiFi 6 Router (Archer AX21) contains a vulnerability that permits unauthenticated local attackers to run arbitrary code with root privileges. This exploit targets the db_dir field within the minidlnad service, which can lead to a stack-based buffer overflow. Exploiting this vulnerability necessitates the connection of a USB flash drive to the router, a common practice among users for sharing files over a local network. Attackers can manipulate files.db, increasing their ability to gain control over the device and potentially compromise the entire network.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved