CVE-2024-5035 describes an unauthenticated command injection vulnerability in the "rftest" network service of the Archer C5400X router (firmware through 1_1.1.6), exposed on TCP ports 8888, 8889, and 8890. This flaw allows a remote, unauthenticated attacker to execute arbitrary commands with elevated privileges on the device. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, the vulnerability has garnered community attention, including media coverage and a public article detailing the fix. There is currently no public exploit code available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| TP-Link | Archer C4500X | >= 0, <= 1_1.1.6CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.5 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.