CVE-2018-19537 describes a remote command execution vulnerability in TP-Link Archer C5 devices (V2_160201_US and earlier firmware). An authenticated attacker with web admin credentials can exploit this by uploading a specially crafted configuration file containing shell metacharacters in the wan_dyn_hostname field. This vulnerability carries a CVSS score of 7.2 (High), indicating a high potential for impact on confidentiality, integrity, and availability, with a network attack vector and low attack complexity. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and it is not listed on the KEV catalog, the vulnerability has a FAUCET Risk Score of 86/100, suggesting a significant risk despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2_160201_usCPE matchmatch criteria | cpe:2.3:o:tp-link:archer_c5_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.