TP-Link VIGI C385 Buffer Overflow Vulnerability Leading to Authenticated Remote Code Execution
Vulnerability
A buffer handling vulnerability has been identified in the TP-Link VIGI C385 V1 Web API. This flaw arises from inadequate input sanitization, potentially allowing memory corruption that could lead to remote code execution. Authenticated attackers might exploit this buffer overflow to execute arbitrary code with elevated privileges.
Impact
Exploitation of this vulnerability could result in unauthorized remote code execution with elevated privileges on the affected device.
Remediation
Users are advised to update to the latest firmware version. The firmware can be downloaded from the TP-Link official website, specific to the region of purchase.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
