Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer C50 firmware versions prior to 'Archer C50(JP)V3230505', Archer C55 firmware versions prior to 'Archer C55(JP)V1230506', and Archer C20 firmware versions prior to 'Archer C20(JP)V1230616'.
Archer C50 firmware versions prior to 'Archer C50(JP)V3230505' and Archer C55 firmware versions prior to 'Archer C55(JP)V1230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary OS command.