Junglewise Threat Intelligence

CVE-2023-33538: TP-Link Multiple Routers command injection in WlanNetworkRpm

CVE-2023-33538 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-06-16

Executive brief

Several older TP-Link router models contain a security flaw that allows an attacker to take full control of the device. These routers are commonly used to provide internet connectivity in small offices and homes. Because these products are at the end of their service life, they will not receive security updates, and users are advised to replace them to prevent unauthorized access to their networks.

Technical details

A command injection vulnerability exists in the '/userRpm/WlanNetworkRpm' component of multiple TP-Link router models. The flaw stems from improper neutralization of special elements (CWE-77) within user-supplied input. An authenticated attacker with low privileges can exploit this over the network to execute arbitrary commands on the underlying operating system. This vulnerability is confirmed to be exploited in the wild. As the affected hardware versions (TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2) are end-of-life, no official patches are expected, and decommissioning is recommended.

Affected products

  • TP-Link TL-WR940N V2, V4
  • TP-Link TL-WR841N V8, V10
  • TP-Link TL-WR740N V1, V2

Timeline

  • 2023-06-09: disclosed: Initial researcher disclosure via GitHub archive
  • 2025-06-16: kev added: CISA added to Known Exploited Vulnerabilities catalog
  • 2025-06-16: advisory: NVD publication date

Related threats