In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
The vulnerability results from the lack of verification of the USER_AGENT field length in HTTP requests handled by the /usr/bin/httpd binary file. Sending a specially crafted USER_AGENT header with excessive length causes a buffer overflow (CWE-787: out-of-bounds write) in the process memory. This results in the possibility of overwriting critical memory areas, which opens the way to taking control of the device.
An attacker can remotely execute arbitrary system commands (RCE) on the device or cause its failure and unavailability. Complete takeover of the device is possible without any authentication.
Patches available from the manufacturer should be applied according to the references. Until an update is performed, it is recommended to restrict access to the device's HTTP interface exclusively to trusted local networks and block access from the Internet using a firewall.
TP-Link RE365 with firmware version V1_180213
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTp Link Re365
HWTp-Link1.0Tp Link Re365 Firmware
OSTp-Link180213
Related vulnerabilities
Command injection w bramkach Omada (TP-Link) po uwierzytelnieniu admina
Zdalne wykonanie poleceń OS bez uwierzytelnienia w routerach TP-Link Omada
TP-Link TL-WR845N — zakodowane na stałe hasło roota (hardcoded password)
TP-Link TL-WR845N — przesyłanie danych uwierzytelniających w postaci jawnego tekstu
RCE z uprawnieniami root w TP-Link Omada ER605 via buffer overflow