Vulnerability record · CVE-2023-33538 · published 7 June 2023
CVE-2023-33538: TP-Link router web interface command injection in WlanNetworkRpm
Tp Link · Tl Wr940n Firmware
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the router web management interface. An authenticated attacker can inject operating system commands through that endpoint, gaining control of the device. Because these are widely deployed consumer/SOHO routers, compromise gives an attacker a persistent foothold on the network edge.
Description
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is in CISA's Known Exploited Vulnerabilities catalog with public exploit code and a high EPSS score, and it allows full compromise of widely deployed edge routers.
What it is
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the router web management interface. An authenticated attacker can inject operating system commands through that endpoint, gaining control of the device. Because these are widely deployed consumer/SOHO routers, compromise gives an attacker a persistent foothold on the network edge.
Impact
An attacker with valid credentials can execute arbitrary commands on the router, leading to full device compromise, configuration changes, traffic interception, and use of the router as a pivot into the internal network. The CVSS vector rates confidentiality, integrity, and availability impact as high.
Attack surface
Reachable over the network via the router's web management interface at /userRpm/WlanNetworkRpm. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates low privileges are required, meaning the attacker needs some level of authentication, but no user interaction is needed.
Exploitation
CVE-2023-33538 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2025-06-16), and public exploit code is referenced. EPSS gives a 30-day exploitation probability of about 41.9% (98.6th percentile), indicating high likelihood of active exploitation.
What to do
- Apply the vendor's firmware update or mitigation guidance from the TP-Link advisory (FAQ 3562) as soon as possible.
- If no patch is available for a given model, discontinue use or replace the device, per CISA's required action.
- Restrict access to the router web management interface to trusted management networks only; never expose it to the internet.
- Change default administrative credentials and enforce strong, unique passwords on all affected routers.
- Monitor CISA KEV guidance and apply BOD 22-01 requirements for any cloud-connected management services.
Detection
- Inspect router and upstream logs for HTTP requests to /userRpm/WlanNetworkRpm containing shell metacharacters or unexpected command strings.
- Monitor for unusual outbound connections or processes originating from affected router models.
- Audit router configuration changes and administrative logins for activity outside normal maintenance windows.
- Use network monitoring to detect command-and-control or scanning traffic sourced from the router's management IP.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-33538 to the Known Exploited Vulnerabilities catalog on 16 June 2025 as "TP-Link Multiple Routers Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 7 July 2025.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/a101e-IoTvul/iotvul/blob/main/tp-link/3/TL-WR940N_TL-WR841N_userRpm_WlanNetworkRpm_Command_Injection. | Broken LinkExploitThird Party Advisory |
| https://web.archive.org/web/20230609111043/https://github.com/a101e-IoTvul/iotvul/blob/main/tp-link/3/TL-WR940N_TL-WR841 | ExploitThird Party Advisory |
| https://www.secpod.com/blog/cisa-issues-warning-on-active-exploitation-of-tp-link-vulnerability-cve-2023-33538/ | Third Party Advisory |
| https://github.com/a101e-IoTvul/iotvul/blob/main/tp-link/3/TL-WR940N_TL-WR841N_userRpm_WlanNetworkRpm_Command_Injection. | Broken LinkExploitThird Party Advisory |
| https://web.archive.org/web/20230609111043/https://github.com/a101e-IoTvul/iotvul/blob/main/tp-link/3/TL-WR940N_TL-WR841 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33538 | US Government Resource |
| https://www.tp-link.com/us/support/faq/3562/ | Product |
Track CVE-2023-33538 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-33538), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.