CVE-2023-33538
KEVHIGH 8.8EPSS 41.9%
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 41.87% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2025-06-16
- Published
- 2023-06-07
- Updated
- 2025-12-20
Proof-of-concept exploits (5)
- a101e-IoTvul/iotvul/blob/main/tp-link/3/TL-WR940N_TL-WR841N_userRpm_WlanNetworkRpm_Comman…
- https://web.archive.org/web/20230609111043/https://github.com/a101e-IoTvul/iotvul/blob/ma…
- https://www.secpod.com/blog/cisa-issues-warning-on-active-exploitation-of-tp-link-vulnera…
- explxx/CVE-2023-335381★ · 2025-06-22
- mrowkoob/CVE-2023-33538-msf1★ · 2025-06-24