← Vulnerability feed

Vulnerability record · CVE-2023-33538 · published 7 June 2023

CVE-2023-33538: TP-Link router web interface command injection in WlanNetworkRpm

Tp Link · Tl Wr940n Firmware

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the router web management interface. An authenticated attacker can inject operating system commands through that endpoint, gaining control of the device. Because these are widely deployed consumer/SOHO routers, compromise gives an attacker a persistent foothold on the network edge.

8.8 CVSS 3.1 High CISA KEV since 16 Jun 2025 EPSS 42% · top 1.4% CWE-77 · Command injection
8.8CVSS 3.1 base score
42%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is in CISA's Known Exploited Vulnerabilities catalog with public exploit code and a high EPSS score, and it allows full compromise of widely deployed edge routers.

What it is

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the router web management interface. An authenticated attacker can inject operating system commands through that endpoint, gaining control of the device. Because these are widely deployed consumer/SOHO routers, compromise gives an attacker a persistent foothold on the network edge.

Impact

An attacker with valid credentials can execute arbitrary commands on the router, leading to full device compromise, configuration changes, traffic interception, and use of the router as a pivot into the internal network. The CVSS vector rates confidentiality, integrity, and availability impact as high.

Attack surface

Reachable over the network via the router's web management interface at /userRpm/WlanNetworkRpm. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates low privileges are required, meaning the attacker needs some level of authentication, but no user interaction is needed.

Exploitation

CVE-2023-33538 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2025-06-16), and public exploit code is referenced. EPSS gives a 30-day exploitation probability of about 41.9% (98.6th percentile), indicating high likelihood of active exploitation.

What to do

  • Apply the vendor's firmware update or mitigation guidance from the TP-Link advisory (FAQ 3562) as soon as possible.
  • If no patch is available for a given model, discontinue use or replace the device, per CISA's required action.
  • Restrict access to the router web management interface to trusted management networks only; never expose it to the internet.
  • Change default administrative credentials and enforce strong, unique passwords on all affected routers.
  • Monitor CISA KEV guidance and apply BOD 22-01 requirements for any cloud-connected management services.

Detection

  • Inspect router and upstream logs for HTTP requests to /userRpm/WlanNetworkRpm containing shell metacharacters or unexpected command strings.
  • Monitor for unusual outbound connections or processes originating from affected router models.
  • Audit router configuration changes and administrative logins for activity outside normal maintenance windows.
  • Use network monitoring to detect command-and-control or scanning traffic sourced from the router's management IP.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-33538 to the Known Exploited Vulnerabilities catalog on 16 June 2025 as "TP-Link Multiple Routers Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 7 July 2025.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-33538 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-9377TP-Link Archer C7 and TL-WR841N Parental Control OS Command InjectionAn OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an au…KEVEPSS 34%analysed7.5CVE-2015-3035TP-Link router directory traversal allows unauthenticated file readA path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by plac…KEVEPSS 84%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed9.9CVE-2023-36355Tp-link tl-wr940n firmware classic buffer overflow vulnerabilityTP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allow…EPSS 32%9.8CVE-2022-25073Tp-link tl-wr841n firmware out-of-bounds write vulnerabilityTL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthent…EPSS 13%9.8CVE-2022-0162Tp-link tl-wr841n firmware cleartext transmission vulnerabilityThe vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in…EPSS 0.67%9.8CVE-2018-12575Tp-link tl-wr841n firmware improper authentication vulnerabilityOn TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of auth…EPSS 2.9%9.8CVE-2018-11714TP-Link router CGI session handling bypass allows unauthenticated actionsTP-Link TL-WR840N v5 and TL-WR841N v13 routers mishandle sessions on the /cgi/ path. Sending a Referer header of http://192.168.0.1/mainFrame.htm cau…EPSS 68%analysed

Source: NIST National Vulnerability Database (record CVE-2023-33538), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.