8
CVSSv3

CVE-2024-57357

CVSSv4: NA | CVSSv3: 8 | CVSSv2: NA | VMScore: 900 | EPSS: 0.00974 | KEV: Not Included
Published: 07/02/2025 Updated: 07/02/2025

Vulnerability Summary

Remote Code Execution in TPLINK TL-WPA 8630 via Command Injection

An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote malicious user to execute arbitrary code via function sub_4256CC, which allows command injection by injecting 'devpwd'.

Vulnerability Trend

Github Repositories

A pre-authentication RCE vulnerability and attack script for a TP-Link TL-WPA8630 device

tplink-wpa8630-rce-vulnerability A pre-authentication RCE vulnerability and attack script for a TP-Link TL-WPA8630 device During my internship at QAX Tiangong Lab, I discovered a pre-authentication RCE vulnerability in the TP-Link TL-WPA8630 device Analyze the httpd file in the /usr/bin directory on port 80 There is a command injection vulnerability in the function sub_4256CC,