CVE-2023-31710

CRITICAL

TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.

Affects 2 products across 1 vendor.

BCS6.59
CVSS 3.19.8
EPSS0.6%
Percentile44th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

◆ SAGE Intelligence — CITED Relevance Research Team

TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to a critical buffer overflow vulnerability, which could allow an attacker to execute arbitrary code with system-level privileges.

BSID: BS-2023-GLOBAL-002064-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-31710?
TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to a critical buffer overflow vulnerability, which could allow an attacker to execute arbitrary code with system-level privileges.
What is the CVSS score for CVE-2023-31710?
CVE-2023-31710 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.6%.
Is CVE-2023-31710 actively exploited?
No confirmed active exploitation of CVE-2023-31710 as of 2026-05-30.
How do I remediate CVE-2023-31710?
Priority: IMMEDIATE.
What systems are affected by CVE-2023-31710?
CVE-2023-31710 affects: Tp-Link, Tp-Link.
Vulnerability Details
CVE IDCVE-2023-31710
BSIDBS-2023-GLOBAL-002064-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2023-08-01
Last Modified2024-11-21
ICS Relevance90%
Weakness (CWE)
SourceNVD
Official Description

TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is due to improper bounds checking when handling user input in the web interface. An attacker could exploit this by sending a specially crafted HTTP request to the device, potentially leading to remote code execution.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Tp-Link Archer Ax21 Firmware
Tp-Link Archer Ax21
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1089 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash543b6ece32d827ff386e84369137f17c9cd4767816821f13a1998805aacd067cb0e7ee40606aee785046aee109b92d3f6f10ab476643684650e238c07c008927
Related CVEs affecting Tp-Link
CVE-2013-2578 10.0 cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC317... CVE-2013-2579 10.0 TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly... CVE-2024-25139 10.0 In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susc... CVE-2023-36355 9.9 TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipSt... CVE-2017-8220 9.9 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 R...
View all Tp-Link CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →