CVE-2020-10881 is a critical vulnerability affecting TP-Link Archer A7 AC1750 routers (Firmware Ver: 190726) that allows unauthenticated remote attackers to execute arbitrary code. The flaw lies in the handling of DNS responses, where a specially crafted DNS message can cause a stack-based buffer overflow, leading to root-level code execution. With a CVSS score of 9.8 (Critical), this vulnerability requires no user interaction or authentication and has a high impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, its high EPSS and FAUCET Risk Score indicate a significant potential threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
190726CPE matchmatch criteria | cpe:2.3:o:tp-link:ac1750_firmware:190726:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.