TP-Link Archer C5400X - RFTest Unauthenticated Command Injection
Published May 27, 2024
8.8
HIGHCVSS 4.0
EPSS 3.24%
Description
The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attacker can gain arbitrary command execution on the device with elevated privileges.This issue affects Archer C4500X: through 1_1.1.6.
Affected products
-
- Version 0StatusaffectedConstraints<=1_1.1.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TP-Link | Archer C4500X | unaffected |
|
No data.
-
- Version 0StatusaffectedConstraints<=1_1.1.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TP-Link | Archer C4500 Firmware | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to firmware version 1_1.1.7.
Metrics
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:H
1 other source (NVD) ▾
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 31, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.24% (0.03244) | 87.88th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.24% (0.03244) | 86.65th | v5 (v2026.06.15) |
| Apr 1, 2026 | 7.86% (0.07863) | 91.97th | v4 (v2025.03.14) |
| Feb 1, 2026 | 6.41% (0.06408) | 90.85th | v4 (v2025.03.14) |
| Jan 30, 2026 | 4.57% (0.04570) | 88.92th | v4 (v2025.03.14) |
| Dec 29, 2025 | 5.96% (0.05963) | 90.34th | v4 (v2025.03.14) |
| Dec 28, 2025 | 4.87% (0.04867) | 89.21th | v4 (v2025.03.14) |
| Nov 24, 2025 | 6.45% (0.06448) | 90.66th | v4 (v2025.03.14) |
| Nov 21, 2025 | 7.86% (0.07863) | 91.65th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.41% (0.01405) | 78.81th | v4 (v2025.03.14) |
| Sep 20, 2025 | 7.86% (0.07863) | 91.68th | v4 (v2025.03.14) |
| Aug 15, 2025 | 5.95% (0.05948) | 90.28th | v4 (v2025.03.14) |
| Jul 6, 2025 | 7.86% (0.07863) | 91.55th | v4 (v2025.03.14) |
| Jul 5, 2025 | 6.52% (0.06520) | 90.66th | v4 (v2025.03.14) |
| Apr 15, 2025 | 2.68% (0.02684) | 84.98th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.32% (0.01319) | 78.51th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00043) | 10.81th | v3 (v2023.03.01) |
| May 27, 2024 | 0.04% (0.00043) | 8.70th | v3 (v2023.03.01) |
References (2)
- https://onekey.com/blog/security-advisory-remote-command-execution-on-tp-link-archer-c5400x/ third-party-advisory
- https://www.tp-link.com/en/support/download/archer-c5400x/#Firmware vendor-advisoryrelease-notes
| Link | Providers | Tags |
|---|---|---|
| https://onekey.com/blog/security-advisory-remote-command-execution-on-tp-link-archer-c5400x/ | third-party-advisory | |
| https://www.tp-link.com/en/support/download/archer-c5400x/#Firmware | vendor-advisoryrelease-notes |
Change history (0)
No recorded changes yet.