Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tp-link
Tp-link archer Airr5 Firmware Tp-link archer Ax3000 Firmware Tp-link archer Ax5400 Firmware Tp-link archer Axe5400 Firmware Tp-link archer Axe75 Firmware |
|
Weaknesses | CWE-78 | |
CPEs | cpe:2.3:o:tp-link:archer_airr5_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_ax3000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_ax5400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_axe5400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_axe75_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Tp-link
Tp-link archer Airr5 Firmware Tp-link archer Ax3000 Firmware Tp-link archer Ax5400 Firmware Tp-link archer Axe5400 Firmware Tp-link archer Axe75 Firmware |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-03-13T13:17:03.724Z
Reserved: 2024-06-17T00:49:41.427Z
Link: CVE-2024-38471

Updated: 2024-08-02T04:12:25.043Z

Status : Awaiting Analysis
Published: 2024-07-04T01:15:02.400
Modified: 2025-03-13T14:15:28.513
Link: CVE-2024-38471

No data.