CVE Explorer
CVE-2026-1457
An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corruption leading to remote code execution. Authenticated attackers may trigger buffer overflow and potentially execute arbitrary code with elevated privileges.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","modules":["Web API"],"platforms":["Linux"],"product":"VIGI C485 V1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"3.1.1 Build 251124 Rel.50371n","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f14bc1a8bc6c3816384b6df05f7241d89adc62fc3d39b884db0f366538ab2745 · sha256:d5d64add9eef1842… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":8.5,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f14bc1a8bc6c3816384b6df05f7241d89adc62fc3d39b884db0f366538ab2745 · sha256:d5d64add9eef1842… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-121","description":"CWE-121 Stack-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f14bc1a8bc6c3816384b6df05f7241d89adc62fc3d39b884db0f366538ab2745 · sha256:d5d64add9eef1842… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/vigi-c385/v1/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f14bc1a8bc6c3816384b6df05f7241d89adc62fc3d39b884db0f366538ab2745 · sha256:d5d64add9eef1842… · /containers/cna/references/0
{"tags":["patch"],"url":"https://www.tp-link.com/kr/support/download/vigi-c385/v1/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f14bc1a8bc6c3816384b6df05f7241d89adc62fc3d39b884db0f366538ab2745 · sha256:d5d64add9eef1842… · /containers/cna/references/1
{"tags":["vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/4931/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f14bc1a8bc6c3816384b6df05f7241d89adc62fc3d39b884db0f366538ab2745 · sha256:d5d64add9eef1842… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.