TP-Link Product Security Update Advisory

Overview

 

An update has been released to address vulnerabilities in TP-Link products. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

TP-Link Archer C5400X 1_1.1.6 or below

 

Resolved Vulnerabilities

 

Arbitrary command execution vulnerability due to unauthenticated command injection in TCP/8888, TCP/8889, and TCP/8890 in TP-Link Archer (CVE-2024-5035)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest vulnerability patches version.

TP-Link Archer C5400X 1_1.1.7 version

 

Referenced Sites

 

[1] CVE-2024-5035 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-5035

[2] Security Advisory: Remote Command Execution on TP-Link Archer C540

https://onekey.com/blog/security-advisory-remote-command-execution-on-tp-link-archer-c5400x/

[3] Download for Archer C5400X V1

https://www.tp-link.com/en/support/download/archer-c5400x/#Firmware