CVE-2026-1457 is an authenticated input sanitization/buffer handling vulnerability in the TP-Link VIGI C385 V1 Web API. The Web API fails to properly validate and/or bound attacker-controlled input, resulting in unsafe buffer handling that can cause memory corruption (buffer overflow). A remote authenticated attacker can trigger the overflow via crafted Web API requests, potentially leading to arbitrary code execution, including execution with elevated privileges depending on the service context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: proof-of-concept exploit for CVE-2026-1457, an authenticated buffer overflow in TP-Link VIGI C385 V1 web API (video.set_resolution via /ds) leading to RCE. Structure: - README.md: Vulnerability write-up with decompiled C snippet showing unsafe strcpy into fixed-size stack buffers (v6/v7) at offset 29, attack scenario, example HTTP request, and embedded exploit code. - exploit.py: Standalone Python exploit using requests + a custom TLSAdapter to disable certificate validation and lower OpenSSL security level; uses pwntools to assemble ARM/Thumb shellcode. Main exploit flow (exploit.py): 1) send_shellcode(): Generates ARM/Thumb shellcode (fork + setsid + connect-back + dupsh) that connects to 192.168.0.102:1337, then sends it via UDP to 192.168.0.100:20002. 2) buffer_overflow(): Sends an authenticated HTTPS POST to https://192.168.0.100/stok=<hardcoded>/ds with JSON invoking video.set_resolution. The 'resolution' field contains an overflow string (0x37 'A's + packed address 0x004f0410) intended to hijack control flow (likely to a gadget/ROP pivot) and execute the previously delivered shellcode. Notable implementation details: - Hardcoded target IP, stok token, gadget address, UDP port, and reverse-shell callback. - Uses browser-like headers (Origin/Referer) but does not implement authentication; it assumes a valid stok is already known. - No robust target detection, offset discovery, or reliability logic; this is an operational PoC tailored to a specific environment/firmware build.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.