CVE-2024-57357

CVSS 3.1 Score 8 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 78

Summary

CVE-2024-57357 is a newly disclosed vulnerability affecting TPLINK's TL-WPA 8630 and TL-WPA8630(US) devices running version 2.0.4 Build 20230427. This issue permits remote attackers to execute arbitrary code through a command injection vulnerability. The vulnerability targets the function sub_4256CC, which can be exploited by injecting the string 'devpwd'. This security flaw poses a significant risk to affected devices, and users are strongly advised to apply the forthcoming patch as soon as it becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share