Back

HIGH

TP-Link Archer C5400X - RFTest Unauthenticated Command Injection

Published May 27, 2024

Description

The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attacker can gain arbitrary command execution on the device with elevated privileges.This issue affects Archer C4500X: through 1_1.1.6.

Affected products

Remediation

Vendor solution

Upgrade to firmware version 1_1.1.7.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ONEKEY
Published May 27, 2024
Updated Aug 1, 2024
Reserved May 16, 2024
CISA Vulnrichment
Updated May 31, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a