CVE-2020-28347 is a critical remote code execution vulnerability affecting TP-Link Archer A7 AC1750 routers with firmware versions prior to 201029. This flaw, an incomplete fix for a previous vulnerability, allows unauthenticated remote attackers to execute arbitrary code by manipulating the slave_mac parameter in the tdpServer. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not on the CISA KEV catalog or actively discussed on social media, a Metasploit module exists, indicating readily available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 201029CPE matchmatch criteria | cpe:2.3:o:tp-link:ac1750_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.