CVE-2024-38471
EUVD-2024-3735204.07.2024, 01:15
Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tp-link | archer_ax3000_firmware | 𝑥 < v1_1.1.3_build_20240415 | ADP |
| tp-link | archer_axe75_firmware | 𝑥 < v1_1.2.0_build_20240320 | ADP |
| tp-link | archer_ax5400_firmware | 𝑥 < v1_1.1.4_build_20240429 | ADP |
| tp-link | archer_axe5400_firmware | 𝑥 < v1_1.0.3_build_20240319 | ADP |
| tp-link | archer_airr5_firmware | 𝑥 < v1_1.0.3_build_20240319 | ADP |
References