← Vulnerability feed

Vulnerability record · CVE-2022-37860 · published 12 September 2022

CVE-2022-37860: TP-Link M7350 web interface pre-auth OS command injection

Tp Link · M7350 Firmware

The web configuration interface of the TP-Link M7350 V3 running firmware 190531 is affected by a pre-authentication OS command injection flaw (CWE-78). Because the flaw is reachable without credentials and over the network, it exposes the device to full compromise by anyone who can reach the management interface.

9.8 CVSS 3.1 Critical EPSS 80% · top 0.4% CWE-78 · OS command injection
9.8CVSS 3.1 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, combined with a very high EPSS score and a reference tagged as an exploit, makes this an urgent patch target.

What it is

The web configuration interface of the TP-Link M7350 V3 running firmware 190531 is affected by a pre-authentication OS command injection flaw (CWE-78). Because the flaw is reachable without credentials and over the network, it exposes the device to full compromise by anyone who can reach the management interface.

Impact

An attacker can execute arbitrary OS commands on the device, gaining full control of confidentiality, integrity and availability as reflected in the CVSS 9.8 rating. This can lead to device takeover, credential or configuration theft, and use of the device as a pivot into the local network.

Attack surface

Reached over the network via the device's web configuration interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The record does not state whether the interface must be exposed to the internet or only the LAN, so exposure depends on deployment.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.80012 (99.6th percentile) and a third-party reference is tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented in the record.

What to do

  • Update the M7350 V3 to the latest firmware from the TP-Link download page referenced in the advisory, which is tagged as the patch source.
  • If immediate patching is not possible, restrict access to the web configuration interface to trusted management networks only and never expose it to the internet.
  • Disable remote/WAN management of the web interface where the product supports it, and place the device behind a firewall that blocks inbound access to its management port.
  • Change default administrative credentials and monitor the device for unexpected configuration changes or reboots.
  • Segment the device on an isolated network so a compromise cannot be used to pivot to other hosts.

Detection

  • Monitor device and network logs for unexpected outbound connections or command execution artifacts originating from the M7350 management interface.
  • Alert on HTTP requests to the M7350 web configuration interface from untrusted or external source addresses.
  • Baseline and review device configuration changes, new admin accounts, or firmware modifications for signs of tampering.
  • Watch for the device being used as a scanning or attack source against other internal hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-37860 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-13649Tp-link m7350 firmware os command injection vulnerabilityTP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).EPSS 2.8%9.8CVE-2019-13650Tp-link m7350 firmware os command injection vulnerabilityTP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5).EPSS 2.8%9.8CVE-2019-13651Tp-link m7350 firmware os command injection vulnerabilityTP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5).EPSS 3.0%9.8CVE-2019-13652Tp-link m7350 firmware os command injection vulnerabilityTP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5).EPSS 2.8%9.8CVE-2019-13653Tp-link m7350 firmware os command injection vulnerabilityTP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).EPSS 2.1%9.8CVE-2019-12103Tp-link m7350 firmware os command injection vulnerabilityThe web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulne…EPSS 3.4%8.8CVE-2019-12104Tp-link m7350 firmware command injection vulnerabilityThe web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injectio…EPSS 4.7%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed

Source: NIST National Vulnerability Database (record CVE-2022-37860), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.