Severity
High
Analysis Summary
CVE-2024-5035
TP-Link Archer C4500X could allow a remote attacker to execute arbitrary commands on the system, caused by improper input validation by the rftest network service. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands with elevated privileges on the device.
Impact
- Gain Access
Indicators of Compromise
CVE
- CVE-2024-5035
Affected Vendors
TP-Link
Affected Products
- TP-Link Archer C4500X 1_1.1.6
Remediation
Upgrade to the latest version of TP-Link Archer C4500X, available from the TP-Link Website.