CVE-2024-57357
CVSS 3.1 Score 8 of 10 (high)
Details
Published Feb 7, 2025
CWE ID 78
Summary
CVE-2024-57357 is a newly disclosed vulnerability affecting TPLINK's TL-WPA 8630 and TL-WPA8630(US) devices running version 2.0.4 Build 20230427. This issue permits remote attackers to execute arbitrary code through a command injection vulnerability. The vulnerability targets the function sub_4256CC, which can be exploited by injecting the string 'devpwd'. This security flaw poses a significant risk to affected devices, and users are strongly advised to apply the forthcoming patch as soon as it becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share