← Vulnerability feed

Vulnerability record · CVE-2023-2646 · published 11 May 2023

CVE-2023-2646: Tp-link archer c7 firmware improper resource shutdown vulnerability

Tp Link · Archer C7 Firmware

A vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Request Parameter Handler. The manipulation leads to denial of service. The attack can only be done within the local network. The associated identifier of this vulnerability is VDB-228775. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

4.5 CVSS 3.1 Medium EPSS 0.32% · top 77.3% CWE-404 · Improper resource shutdown
4.5CVSS 3.1 base score, v2 5.0
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Request Parameter Handler. The manipulation leads to denial of service. The attack can only be done within the local network. The associated identifier of this vulnerability is VDB-228775. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://vuldb.com/?ctiid.228775 Third Party Advisory
https://vuldb.com/?id.228775 Third Party Advisory
https://vuldb.com/?ctiid.228775 Third Party Advisory
https://vuldb.com/?id.228775 Third Party Advisory

Track CVE-2023-2646 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-9377TP-Link Archer C7 and TL-WR841N Parental Control OS Command InjectionAn OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an au…KEVEPSS 34%analysed7.5CVE-2015-3035TP-Link router directory traversal allows unauthenticated file readA path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by plac…KEVEPSS 84%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed9.8CVE-2020-35575Tp-link wa901nd firmware vulnerabilityA password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web pan…EPSS 7.6%8.0CVE-2023-39224Tp-link archer c7 firmware os command injection vulnerabilityArcher C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to…EPSS 0.40%5.4CVE-2026-5363Tp-link archer c7 firmware inadequate encryption strength vulnerabilityInadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interfa…EPSS 0.11%7.8CVE-2018-8639Windows Win32k memory handling flaw allows privilege elevationThe Win32k component in Windows fails to properly handle objects in memory, creating an elevation of privilege vulnerability. It affects a broad rang…KEVEPSS 22%analysed7.8CVE-2018-8611Windows Kernel Memory Handling Elevation of PrivilegeThe Windows kernel fails to properly handle objects in memory, allowing a local attacker to elevate privileges. The flaw affects a broad set of Windo…KEVEPSS 4.2%analysed

Source: NIST National Vulnerability Database (record CVE-2023-2646), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.