Buffer Overflow Vulnerability in TP-Link AX1800 WiFi 6 Router
CVE-2023-28760

Currently unrated

Key Information:

Vendor

TP-Link

Vendor
CVE Published:
2 October 2025

What is CVE-2023-28760?

The TP-Link AX1800 WiFi 6 Router (Archer AX21) contains a vulnerability that permits unauthenticated local attackers to run arbitrary code with root privileges. This exploit targets the db_dir field within the minidlnad service, which can lead to a stack-based buffer overflow. Exploiting this vulnerability necessitates the connection of a USB flash drive to the router, a common practice among users for sharing files over a local network. Attackers can manipulate files.db, increasing their ability to gain control over the device and potentially compromise the entire network.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.