CVE-2023-33538
Unknown
Unknown - Not Provided
BaseFortify
Vulnerability report for CVE-2023-33538, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2023-06-07
Last updated on: 2025-10-27
Assigner: MITRE
Description
Description
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | tl-wr940n_firmware | * |
| tp-link | tl-wr940n | 2.0 |
| tp-link | tl-wr940n | 4.0 |
| tp-link | tl-wr841n_firmware | * |
| tp-link | tl-wr841n | 8.0 |
| tp-link | tl-wr841n | 10.0 |
| tp-link | tl-wr740n_firmware | * |
| tp-link | tl-wr740n | 1.0 |
| tp-link | tl-wr740n | 2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-77 | The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component. |