CVE-2023-33538: TP-Link Multiple Routers Command Injection Vulnerability
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Other sources
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of the impacted TP-Link routers: TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 (command injection via component /userRpm/WlanNetworkRpm), especially if the products are end-of-life (EoL) and/or end-of-service (EoS).
Event History
Frequently Asked Questions
What is CVE-2023-33538?
CVE-2023-33538 is a command injection vulnerability in TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 routers.
How severe is CVE-2023-33538?
CVE-2023-33538 has a severity score of 8.8, which is considered high.
Which TP-Link router models are affected by CVE-2023-33538?
CVE-2023-33538 affects TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 routers.
What is the component that contains the command injection vulnerability?
The command injection vulnerability in CVE-2023-33538 is found in the /userRpm/WlanNetworkRpm component.
Is there a fix available for CVE-2023-33538?
Currently, there is no official fix available for CVE-2023-33538. It is recommended to update to the latest firmware when it becomes available or apply any provided patches from the vendor.