ZDI-CAN-19703: ZDI-23-377: TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AX1800 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19703?
ZDI-CAN-19703 is classified as a critical vulnerability due to its potential to allow arbitrary code execution by network-adjacent attackers.
How do I fix ZDI-CAN-19703?
To fix ZDI-CAN-19703, users should update their TP-Link AX1800 router firmware to the latest version as recommended by TP-Link.
What type of attacks are possible with ZDI-CAN-19703?
ZDI-CAN-19703 enables network-adjacent attackers to execute arbitrary code without authentication on vulnerable TP-Link routers.
Which devices are affected by ZDI-CAN-19703?
ZDI-CAN-19703 affects TP-Link AX1800 routers, specifically the EX20v model.
Is authentication required to exploit ZDI-CAN-19703?
No, authentication is not required to exploit ZDI-CAN-19703, making it particularly dangerous for vulnerable devices.