TP-Link Vulnerabilities and Affected Products
Vulnerabilities associated with Archer AX3000.
Products
Clear product- tl-wr886n_firmware14 vulnerabilities
- AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3)12 vulnerabilities
- ac1350_firmware11 vulnerabilities
- N300 Wireless Access Point (EAP115)10 vulnerabilities
- n300_firmware10 vulnerabilities
- Archer A79 vulnerabilities
- ER7206 Omada Gigabit VPN Router9 vulnerabilities
- TL-WR841N8 vulnerabilities
- TL-WR940N8 vulnerabilities
- Omada ER6057 vulnerabilities
- tl-wdr7660_firmware6 vulnerabilities
- tl-wr941nd5 vulnerabilities
- AC17504 vulnerabilities
- Archer AX30004 vulnerabilities
- Archer AX54004 vulnerabilities
- tl-wr840n_firmware4 vulnerabilities
- VN020 F3v(T)4 vulnerabilities
- Archer Air R53 vulnerabilities
- Archer AX213 vulnerabilities
- Archer AXE753 vulnerabilities
- Archer C53 vulnerabilities
- Archer C503 vulnerabilities
- TL-WR902AC3 vulnerabilities
- tl-wr902ac_firmware3 vulnerabilities
- TP-Link TL-WRN841N3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-38471MEDIUM | Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi. CWE-78Jul 4, 2024 | CVSS6.8v3.1 | EPSS0.362% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21833HIGH | TP-Link archer_ax3000_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi. CWE-78Jan 10, 2024 | CVSS8.8v3.1 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21821HIGH | Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands. CWE-78Jan 10, 2024 | CVSS8.0v3.1 | EPSS0.446% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21773HIGH | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings. CWE-78Jan 10, 2024 | CVSS8.8v3.1 | EPSS0.531% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |