Code Injection in Archer AX50 - CVE-2022-30075
Published: June 10, 2022 / Updated: September 12, 2022
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to a flaw in the backup and restore functionality. A remote administrator on the local network can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2022-30075
Links to Public Exploits and PoC-codes
- Exploit #8359 - CVE-2022-30075 () (September 12, 2022)
- Exploit #8042 - TP-Link Router AX50 firmware 210730 - Remote Code Execution (RCE) (Authenticated) (June 15, 2022)
- Exploit #8027 - CVE-2022-30075 (NEW EXPLOIT FOR TP LINK) (June 12, 2022)
- Exploit #8026 - CVE-2022-30075 () (June 12, 2022)
- Exploit #8024 - CVE-2022-30075 (Tp-Link Archer AX50 Authenticated RCE (CVE-2022-30075)) (June 12, 2022)