ZERO-DAY ALERT: Automated Discovery of Critical CWMP Stack Overflow in TP-Link Routers
A critical zero-day vulnerability allowing remote code execution was found in TP-Link Archer AX10/AX1500 routers. The vulnerability stems from a stack-based buffer overflow in the CWMP implementation. A malicious CWMP server URL, easily set within router configuration, triggers the exploit. The vulnerability affects multiple firmware versions across various hardware revisions. Over 4,000 vulnerable devices were identified online. The researcher reported the vulnerability to TP-Link on May 11th, 2024, but a patch remains absent. This flaw grants complete control over affected routers. The vulnerability exploits a flawed string handling function, neglecting proper input size validation. The researcher used automated taint analysis to discover this vulnerability. Public disclosure is currently underway.