MeshyJSON: A TP-Link tdpServer JSON Stack Overflow
ID: e6236e5e-d72e-52d2-8765-5769cd0f2352
STIX ID: report--e6236e5e-d72e-52d2-8765-5769cd0f2352
Feed Name: NCC Research
This NCC Group blog details a remote code execution vulnerability in TP‑Link Archer AX21's tdpServer (mesh TDP protocol) caused by an unchecked onemesh_support_version JSON array that overflows a fixed 32‑byte stack buffer; the write‑up explains two network flows to reach the vulnerable function, the heap spray and virtualized heap (VHeap) techniques used to bypass ASLR and craft deterministic cJSON allocations, a ROP-based payload to invoke system(), exploitation reliability constraints, and notes that TP‑Link patched the issue in firmware Archer AX21(US)_V3.6_1.1.3 Build 20221125.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
