TP-Link Archer AX10
cpe:2.3:h:tp-link:archer_ax10:*:*:*:*:*:*:*, +1 more
- < 1.2.1
A stack-based buffer overflow vulnerability has been identified in the CWMP (TR-069) implementation of TP-Link Archer AX10 and AX1500 routers. This vulnerability allows authenticated attackers to execute arbitrary code remotely, but requires a Man-In-The-Middle (MITM) attack to exploit. The issue is present in multiple firmware versions across different hardware releases of the affected router models.
Exploitation of this vulnerability leads to unauthorized remote code execution on the affected router, with the executed code running with root privileges.
The vulnerability can be reproduced by sending a crafted CWMP SOAP message, specifically one that includes the 'SetParameterValues' operation. This message must be intercepted and modified during transmission to exploit the buffer overflow. The CWMP service on the router will process the message, leading to a stack-based buffer overflow that can be exploited to execute arbitrary code.
Users are advised to update their routers to the latest firmware version. For the AX10, this means updating to version 1.2.1 or later. AX1500 users should update to version 1.3.12 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.