{"id":"CVE-2026-85384","title":"A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file","summary":"A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local n…","severity":"high","cvss":8.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-121"],"vendor":"TP-Link Systems Inc.","product":"RE210 AC750","affected":["re210_ac750 <= 3.14.2 Build 141218 Rel.36430n (EU)","re210_ac750 <= 3.14.2 Build 171205 Rel.71984n (US)"],"published":"2026-09-08","updated":"2026-09-10","sourceUpdated":"2026-09-10T04:18:18.530","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85384","references":[{"url":"https://www.tp-link.com/en/support/faq/3562/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-09T20:38:22.751092Z"},"cvssSource":"cna","epss":0.0021,"epssPercentile":0.11423,"ingestedAt":"2026-09-08T19:08:49.637Z","slug":"CVE-2026-85384","body":"## Overview\n\nA stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.\n\n\n\n\n\nSuccessful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}