VYPR
Unrated severityNVD Advisory· Published Oct 24, 2023· Updated Sep 11, 2024

CVE-2023-46371

CVE-2023-46371

Description

TP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack overflow in `upgradeInfoJsonToBin` on TP-Link TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 allows potential code execution.

Vulnerability

A stack overflow vulnerability exists in TP-Link TL-WDR7660 firmware version 2.0.30 and TL-WR886N firmware version 2.0.12. The flaw resides in the upgradeInfoJsonToBin function, which processes a crafted JSON input without proper bounds checking, leading to a stack buffer overflow [1].

Exploitation

An unauthenticated attacker with network access to the affected device can send a specially crafted HTTP request that triggers the vulnerable upgradeInfoJsonToBin function. The attacker does not require prior authentication or user interaction; the overflow occurs during normal processing of the firmware upgrade information input [1].

Impact

Successful exploitation allows the attacker to corrupt the stack memory, potentially leading to arbitrary code execution with root privileges on the device. This would give the attacker full control over the router, enabling traffic interception, configuration changes, or further propagation into the network [1].

Mitigation

TP-Link has not released a fixed firmware version as of the publication date. Users should monitor TP-Link's official support channels for updates. No workarounds have been disclosed; until a patch is available, restrict network access to the router's management interface to trusted hosts only [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.