CVE-2024-42815: TP-Link RE365 Firmware

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

Affected products

  • TP-Link RE365 Firmware: version 180213 only

Published 2024-08-19. Last modified 2026-06-17.