CVE-2022-30075

HIGH EXPLOITED

Tp-link Archer Ax50 Firmware < 210730 - Remote Code Execution

Title source: rule

Description

In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.

Exploits (5)

exploitdb WORKING POC
by Tomas Melicher · pythonremotehardware
https://www.exploit-db.com/exploits/50962
nomisec WORKING POC 231 stars
by aaronsvk · remote-auth
https://github.com/aaronsvk/CVE-2022-30075
nomisec WORKING POC 3 stars
by SAJIDAMINE · remote-auth
https://github.com/SAJIDAMINE/CVE-2022-30075
nomisec WORKING POC 1 stars
by M4fiaB0y · remote
https://github.com/M4fiaB0y/CVE-2022-30075
nomisec WORKING POC
by RhestCorp · remote-auth
https://github.com/RhestCorp/TP-L-NK-SIZMA-EXPLO-T

Scores

CVSS v3 8.8
EPSS 0.8926
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-11-26
Status published
Products (1)
tp-link/archer_ax50_firmware < 210730
Published Jun 09, 2022
Tracked Since Feb 18, 2026