CVE-2022-24354 is a critical arbitrary code execution vulnerability affecting TP-Link AC1750 routers running firmware prior to version 1.1.4 Build 20211022 rel.59103(5553). This flaw, residing in the NetUSB.ko module, stems from an integer overflow due to improper validation of user-supplied data. With a CVSS score of 8.8 (High), it allows unauthenticated, network-adjacent attackers to execute code as root with low attack complexity. Despite its severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 211210CPE matchmatch criteria | cpe:2.3:o:tp-link:ac1750_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.