CVE-2023-33538: TP-Link Multiple Routers Command Injection Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-06-16. EPSS: 41.6% chance of exploitation in the next 30 days.

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .

Affected products

  • TP-Link Tl-WR740N Firmware: affected versions not specified
  • TP-Link TL-WR841N Firmware: affected versions not specified
  • TP-Link Tl-WR940N Firmware: affected versions not specified

Published 2023-06-07. Last modified 2026-06-17.