Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
CVE ID: CVE-2024-38471
Vendor: TP-LINK, TP-LINK, TP-LINK, TP-LINK, TP-LINK
Product: Archer AX3000, Archer AXE75, Archer AX5400, Archer Air R5, Archer AXE5400
EPSS Score: 0.41% (probability of being exploited)
EPSS Percentile: 58.35% (scored less or equal to compared to others)
EPSS Date: 2025-04-11 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: total
SSVC Automatable: false