github.com
https://github.com/ThottySploity/CVE-2024-53375 CVE-2024-53375
HIGH
TP-Link archer_axe75_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2024-53375 has a selected CVSS score of 8.0 (high); EIP currently links 1 repository PoC.
Description
An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the activation of the HomeShield functionality.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 26, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 3, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
archer_axe75_firmwareBrowse TP-Link / archer_axe75_firmwareDefault status: unknown | VulnCheck, CVE List | 1.2.2_build_20240827 | affected |
Proofs of concept
1Repository PoCs
GitHubThottySploity/CVE-2024-53375Repository PoCby ThottySploityStars: 21Not analyzed6 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-53375 thottysploity.github.io
https://thottysploity.github.io/posts/cve-2024-53375