Vulnerability record · CVE-2022-37860 · published 12 September 2022
CVE-2022-37860: TP-Link M7350 web interface pre-auth OS command injection
Tp Link · M7350 Firmware
The web configuration interface of the TP-Link M7350 V3 running firmware 190531 is affected by a pre-authentication OS command injection flaw (CWE-78). Because the flaw is reachable without credentials and over the network, it exposes the device to full compromise by anyone who can reach the management interface.
Description
The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, combined with a very high EPSS score and a reference tagged as an exploit, makes this an urgent patch target.
What it is
The web configuration interface of the TP-Link M7350 V3 running firmware 190531 is affected by a pre-authentication OS command injection flaw (CWE-78). Because the flaw is reachable without credentials and over the network, it exposes the device to full compromise by anyone who can reach the management interface.
Impact
An attacker can execute arbitrary OS commands on the device, gaining full control of confidentiality, integrity and availability as reflected in the CVSS 9.8 rating. This can lead to device takeover, credential or configuration theft, and use of the device as a pivot into the local network.
Attack surface
Reached over the network via the device's web configuration interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The record does not state whether the interface must be exposed to the internet or only the LAN, so exposure depends on deployment.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.80012 (99.6th percentile) and a third-party reference is tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented in the record.
What to do
- Update the M7350 V3 to the latest firmware from the TP-Link download page referenced in the advisory, which is tagged as the patch source.
- If immediate patching is not possible, restrict access to the web configuration interface to trusted management networks only and never expose it to the internet.
- Disable remote/WAN management of the web interface where the product supports it, and place the device behind a firewall that blocks inbound access to its management port.
- Change default administrative credentials and monitor the device for unexpected configuration changes or reboots.
- Segment the device on an isolated network so a compromise cannot be used to pivot to other hosts.
Detection
- Monitor device and network logs for unexpected outbound connections or command execution artifacts originating from the M7350 management interface.
- Alert on HTTP requests to the M7350 web configuration interface from untrusted or external source addresses.
- Baseline and review device configuration changes, new admin accounts, or firmware modifications for signs of tampering.
- Watch for the device being used as a scanning or attack source against other internal hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tp-link.com/uk/support/download/m7350/v3/#Firmware | PatchRelease NotesVendor Advisory |
| https://www.yuque.com/docs/share/fca60ef9-e5a4-462a-a984-61def4c9b132 | ExploitPatchThird Party Advisory |
| https://www.tp-link.com/uk/support/download/m7350/v3/#Firmware | PatchRelease NotesVendor Advisory |
| https://www.yuque.com/docs/share/fca60ef9-e5a4-462a-a984-61def4c9b132 | ExploitPatchThird Party Advisory |
Track CVE-2022-37860 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-37860), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.