CVE-2020-28347: TP-Link AC1750 Firmware
Critical severity, CVSS 9.8. EPSS: 75.4% chance of exploitation in the next 30 days.
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.
Affected products
- TP-Link AC1750 Firmware: before 201029 (fixed in 201029)
Published 2020-11-08. Last modified 2026-06-17.