Vulnerability record · CVE-2018-19537 · published 26 November 2018
CVE-2018-19537: Tp-link archer c5 firmware unrestricted file upload vulnerability
Tp Link · Archer C5 Firmware
TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.
Description
TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/JackDoan/TP-Link-ArcherC5-RCE | ExploitThird Party Advisory |
| https://github.com/JackDoan/TP-Link-ArcherC5-RCE | ExploitThird Party Advisory |
Track CVE-2018-19537 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19537), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.