CVE-2023-33538: TP-Link Multiple Routers Command Injection Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-06-16. EPSS: 41.6% chance of exploitation in the next 30 days.
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
Affected products
- TP-Link Tl-WR740N Firmware: affected versions not specified
- TP-Link TL-WR841N Firmware: affected versions not specified
- TP-Link Tl-WR940N Firmware: affected versions not specified
Published 2023-06-07. Last modified 2026-06-17.