Loading HuntDB...

TP-Link Multiple Routers Command Injection Vulnerability

Added June 16, 2025 Due July 7, 2025 CVE-2023-33538
On Track TP-Link / Multiple Routers CWE-77

Description

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.06.16
Catalog Released
June 16, 2025
Days Until Due
18 days
Last Updated
2 days, 9 hours ago