← Vulnerability feed

Vulnerability record · CVE-2020-28347 · published 8 November 2020

CVE-2020-28347: TP-Link Archer A7 tdpServer OS command injection via slave_mac

Tp Link · Ac1750 Firmware

tdpServer on TP-Link Archer A7 AC1750 devices before firmware 201029 mishandles shell quotes in the slave_mac parameter, allowing OS command injection. It is an incomplete fix for CVE-2020-10882, so the same attack path remains open on unpatched units.

9.8 CVSS 3.1 Critical EPSS 75% · top 0.5% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code, and a very high EPSS score make this an urgent remote code execution risk.

What it is

tdpServer on TP-Link Archer A7 AC1750 devices before firmware 201029 mishandles shell quotes in the slave_mac parameter, allowing OS command injection. It is an incomplete fix for CVE-2020-10882, so the same attack path remains open on unpatched units.

Impact

A remote attacker can execute arbitrary code on the router, gaining full control of the device and its network position.

Attack surface

Reachable over the network through the tdpServer service with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV, but EPSS is 0.76621 (99.5th percentile) and multiple references are tagged Exploit, including a Metasploit pull request, indicating public exploit code exists.

What to do

  • Update Archer A7 AC1750 firmware to version 201029 or later, which contains the corrected fix.
  • If patching is not possible, block external access to the tdpServer port and restrict management interfaces to trusted networks.
  • Segment or isolate affected routers from sensitive internal networks until they are updated.
  • Monitor TP-Link advisories for any follow-up fix, since this CVE is itself an incomplete fix for CVE-2020-10882.

Detection

  • Inspect tdpServer request logs for slave_mac values containing shell metacharacters such as quotes, semicolons, pipes or backticks.
  • Alert on unexpected outbound connections or processes spawned by tdpServer on the router.
  • Watch for known exploit traffic patterns from the referenced Pwn2Own and Metasploit materials against the tdpServer endpoint.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28347 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10885Tp-link ac1750 firmware improper input validation vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…EPSS 6.5%9.8CVE-2020-10886Tp-link ac1750 firmware os command injection vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…EPSS 5.0%9.8CVE-2020-10887Tp-link ac1750 firmware vulnerabilityThis vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not…EPSS 3.7%9.8CVE-2020-10888Tp-link ac1750 firmware improper authentication vulnerabilityThis vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 router…EPSS 2.2%9.8CVE-2020-10881Tp-link ac1750 firmware stack-based buffer overflow vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…EPSS 9.3%8.8CVE-2022-24352Tp-link ac1750 firmware out-of-bounds read vulnerabilityThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 211210 routers. A…EPSS 0.74%8.8CVE-2022-24353Tp-link ac1750 firmware out-of-bounds read vulnerabilityThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 1.1.4 Build 20211022 rel.5…EPSS 0.74%8.8CVE-2022-24354Tp-link ac1750 firmware integer overflow vulnerabilityThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 1.1.4 Build 20211…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2020-28347), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.