CVE-2020-28347: TP-Link AC1750 Firmware

Critical severity, CVSS 9.8. EPSS: 75.4% chance of exploitation in the next 30 days.

tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.

Affected products

  • TP-Link AC1750 Firmware: before 201029 (fixed in 201029)

Published 2020-11-08. Last modified 2026-06-17.