OS Command Injection in Archer C4500X - CVE-2024-5035

 

OS Command Injection in Archer C4500X - CVE-2024-5035

Published: May 28, 2024


Vulnerability identifier: #VU89842
CSH Severity: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Red
CVE-ID: CVE-2024-5035
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Archer C4500X
Software vendor:
TP-Link

Description

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation within the "rftest" service. A remote unauthenticated attacker can send specially crafted requests to ports TCP/8888, TCP/8889, or TCP/8890 and execute arbitrary OS commands on the target device.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links