CVE-2023-33538

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component...

Basic Information

CVE State
PUBLISHED
Reserved Date
May 22, 2023
Published Date
June 07, 2023
Last Updated
December 20, 2025
Vendor
n/a
Product
n/a
Description
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
Tags
edge cisa

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

Score
90.57% (Percentile: 99.63%) as of 2026-05-31

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:33:09 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:33:02 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel