Stack-Based Buffer Overflow in RE210 AC750 by TP-Link
CVE-2026-85384

8.5HIGH

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-85384?

A stack-based buffer overflow vulnerability in the httpd component of TP-Link's RE210 AC750 arises due to insufficient bounds checking within the splitString function during the handling of an uploaded configuration file. An authenticated attacker on the local network can exploit this flaw by uploading a specifically crafted configuration file that triggers the overflow. This exploitation could potentially lead to unauthorized access to sensitive information, modification of device configurations, and disruptions in device functionality or availability.

Affected Version(s)

RE210 AC750 0 <= 3.14.2 Build 141218 Rel.36430n (EU)

RE210 AC750 0 <= 3.14.2 Build 171205 Rel.71984n (US)

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Ace Bengil (Archan6el)
.