CVE-2024-53375
massAuthenticated command-injection RCE in TP-Link Archer routers (HomeShield)
CVE-2024-53375 is an authenticated remote code execution flaw (OS command injection, CWE-78) in the 'tmp_get_sites' function of the HomeShield feature on TP-Link Archer series routers. An attacker with valid low-privileged access to the router's management interface on an adjacent network (CVSS vector AV:A/PR:L) can trigger the flaw with crafted input to that function, and the router remains exploitable even when HomeShield is not enabled. Successful exploitation yields arbitrary command execution on the device, with high impact on confidentiality, integrity, and availability. Owners of TP-Link Archer routers that ship the HomeShield functionality are in scope; a precise list of affected models and firmware versions has not been published in the available data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known so far, but EPSS assigns a 40.5% probability of exploitation within 30 days (99th percentile), and recent IoT botnet activity targeting routers raises the stakes.
What to do: Identify your Archer model and current firmware version on TP-Link's support site and install the latest firmware as soon as a fix is published; no fixed version numbers are confirmed in the available data. Because the flaw requires authenticated, adjacent-network access, restrict router administration to trusted LAN clients, use a strong admin password, and disable WAN-side/remote management until patched. Note that disabling HomeShield is not a mitigation, since the flaw is exploitable even when the feature is not activated.
| TP-Link Archer series routers with the HomeShield feature | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the activation of the HomeShield functionality.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H