High severity7.2NVD Advisory· Published Apr 9, 2024· Updated Jun 17, 2026
CVE-2023-49908
CVE-2023-49908
Description
A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the profile parameter at offset 0x0045abc8 of the httpd_portal binary shipped with v5.1.0 Build 20220926 of the EAP225.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4v5.1.0 Build 20220926+ 1 more
- (no CPE)range: v5.1.0 Build 20220926
- (no CPE)range: v5.1.0 Build 20220926
- Tp-Link/N300 Wireless Access Point (EAP115)v5Range: v5.0.4 Build 20220216
Patches
Vulnerability mechanics
References
2- talosintelligence.com/vulnerability_reports/TALOS-2023-1888nvdExploitThird Party Advisory
- www.talosintelligence.com/vulnerability_reports/TALOS-2023-1888nvd
News mentions
0No linked articles in our index yet.