CVE-2024-21833

8.8HIGH

Key Information

Vendor
TP-Link
Status
Archer AX3000
Archer AX5400
Archer AXE75
Deco X50
Vendor
CVE Published:
11 January 2024

Badges

😄 Trended👾 Exploit Exists📰 News Worthy

Summary

A critical vulnerability, identified as CVE-2024-21833, has been discovered in multiple TP-LINK products, allowing attackers to execute arbitrary OS commands without authentication. This flaw affects various router models, potentially enabling malicious actors to disrupt services, steal sensitive information, or enlist devices into botnets. There is evidence of active exploitation of this vulnerability, with discussions of potential sharing of exploit tools in underground forums. It is crucial for users to update their firmware to address the security concerns and consider implementing network segmentation and firewall rules to restrict access to vulnerable devices.

Affected Version(s)

Archer AX3000 = firmware versions prior to "Archer AX3000(JP)_V1_1.1.2 Build 20231115"

Archer AX5400 = firmware versions prior to "Archer AX5400(JP)_V1_1.1.2 Build 20231115"

Archer AXE75 = firmware versions prior to "Archer AXE75(JP)_V1_231115"

News Articles

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability started trending.

  • 👾

    Exploit exists.

  • First article discovered by Penetration Testing

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database3 News Article(s)
.