CVE-2023-37284: TP-Link Archer c20 Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication.

Affected products

  • TP-Link Archer c20 Firmware: before 230616 (fixed in 230616)

Published 2023-09-06. Last modified 2026-06-17.