Vulnerability record · CVE-2020-28347 · published 8 November 2020
CVE-2020-28347: TP-Link Archer A7 tdpServer OS command injection via slave_mac
Tp Link · Ac1750 Firmware
tdpServer on TP-Link Archer A7 AC1750 devices before firmware 201029 mishandles shell quotes in the slave_mac parameter, allowing OS command injection. It is an incomplete fix for CVE-2020-10882, so the same attack path remains open on unpatched units.
Description
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code, and a very high EPSS score make this an urgent remote code execution risk.
What it is
tdpServer on TP-Link Archer A7 AC1750 devices before firmware 201029 mishandles shell quotes in the slave_mac parameter, allowing OS command injection. It is an incomplete fix for CVE-2020-10882, so the same attack path remains open on unpatched units.
Impact
A remote attacker can execute arbitrary code on the router, gaining full control of the device and its network position.
Attack surface
Reachable over the network through the tdpServer service with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is 0.76621 (99.5th percentile) and multiple references are tagged Exploit, including a Metasploit pull request, indicating public exploit code exists.
What to do
- Update Archer A7 AC1750 firmware to version 201029 or later, which contains the corrected fix.
- If patching is not possible, block external access to the tdpServer port and restrict management interfaces to trusted networks.
- Segment or isolate affected routers from sensitive internal networks until they are updated.
- Monitor TP-Link advisories for any follow-up fix, since this CVE is itself an incomplete fix for CVE-2020-10882.
Detection
- Inspect tdpServer request logs for slave_mac values containing shell metacharacters such as quotes, semicolons, pipes or backticks.
- Alert on unexpected outbound connections or processes spawned by tdpServer on the router.
- Watch for known exploit traffic patterns from the referenced Pwn2Own and Metasploit materials against the tdpServer endpoint.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-28347 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28347), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.