CVE-2024-21773
11.01.2024, 00:15
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.
Vendor | Product | Version |
---|---|---|
tp-link | archer_ax3000_firmware | 𝑥 < 1.1.2 |
tp-link | archer_ax5400_firmware | 𝑥 < 1.1.2 |
tp-link | deco_x50_firmware | 𝑥 < 1.4.1 |
tp-link | deco_xe200_firmware | 𝑥 < 1.2.5 |
𝑥
= Vulnerable software versions
References