CRITICAL🇵🇱 Wersja polska

CVE-2024-42815

CVSS 9.8v3.1pub. 2024-08-19upd. 2025-07-09

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

🤖 AI Analysis
How it works

The vulnerability results from the lack of verification of the USER_AGENT field length in HTTP requests handled by the /usr/bin/httpd binary file. Sending a specially crafted USER_AGENT header with excessive length causes a buffer overflow (CWE-787: out-of-bounds write) in the process memory. This results in the possibility of overwriting critical memory areas, which opens the way to taking control of the device.

Impact

An attacker can remotely execute arbitrary system commands (RCE) on the device or cause its failure and unavailability. Complete takeover of the device is possible without any authentication.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Until an update is performed, it is recommended to restrict access to the device's HTTP interface exclusively to trusted local networks and block access from the Internet using a firewall.

Who is affected

TP-Link RE365 with firmware version V1_180213

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Tp Link Re365

    HW
    Tp-Link
    1.0
  • Tp Link Re365 Firmware

    OS
    Tp-Link
    180213
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-7850CRITICAL9.3PL ✓same vendor

Command injection w bramkach Omada (TP-Link) po uwierzytelnieniu admina

CVE-2025-6542CRITICAL9.3PL ✓same vendor

Zdalne wykonanie poleceń OS bez uwierzytelnienia w routerach TP-Link Omada

CVE-2024-57040CRITICAL9.8PL ✓same vendor

TP-Link TL-WR845N — zakodowane na stałe hasło roota (hardcoded password)

CVE-2024-46340CRITICAL9.8PL ✓same vendor

TP-Link TL-WR845N — przesyłanie danych uwierzytelniających w postaci jawnego tekstu

CVE-2024-25139CRITICAL10.0PL ✓same vendor

RCE z uprawnieniami root w TP-Link Omada ER605 via buffer overflow