CVE-2026-1457

HIGH

TP-Link VIGI C385 V1 - Buffer Overflow

Title source: llm

Description

An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corruption leading to remote code execution. Authenticated attackers may trigger buffer overflow and potentially execute arbitrary code with elevated privileges.

Exploits (2)

github WRITEUP 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-1457
nomisec WRITEUP
by ii4gsp · poc
https://github.com/ii4gsp/CVE-2026-1457

Scores

CVSS v3 8.8
EPSS 0.0011
EPSS Percentile 29.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-121
Status published
Products (1)
tp-link/vigi_c385_firmware < 3.1.1
Published Jan 29, 2026
Tracked Since Feb 18, 2026