Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-44448
6.8MEDIUM
What is CVE-2023-44448?
The stack-based buffer overflow vulnerability identified in the TP-Link Archer A54 routers arises from inadequate validation of user-supplied data length before it is copied to a fixed-length stack-based buffer in the libcmm.so file. This flaw can be exploited by network-adjacent attackers who, after successful authentication, can execute arbitrary code within the context of root. Protecting against this vulnerability requires immediate attention to ensure network security and prevent unauthorized access.
Affected Version(s)
Archer A54 0.9.1 0.4 v0001.0 Build 211108 Rel.33223n(5553)