Unrated severityNVD Advisory· Published Mar 25, 2020· Updated Aug 4, 2024
CVE-2020-10881
CVE-2020-10881
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9660.
Affected products
1- Range: Firmware Ver: 190726
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.zerodayinitiative.com/advisories/ZDI-20-333/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.