CVE-2023-49074: TP-Link EAP225 Firmware

High severity, CVSS 7.5. EPSS: 13.5% chance of exploitation in the next 30 days.

A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of network requests can lead to reset to factory settings. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.

Affected products

  • TP-Link EAP225 Firmware: version 5.1.0 only

Published 2024-04-09. Last modified 2026-06-17.