CVE-2021-44632 is a critical buffer overflow vulnerability affecting TP-LINK WR-886N routers (firmware version 20190826 2.3.8). This flaw, residing in the /cloud_config/router_post/upgrade_info feature, allows unauthenticated attackers to execute arbitrary code on the device by sending a specially crafted POST request. With a CVSS score of 9.8, it poses a severe risk of complete compromise (confidentiality, integrity, and availability). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20190826_2.3.8CPE matchmatch criteria | cpe:2.3:o:tp-link:tl-wr886n_firmware:20190826_2.3.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.