CVE-2024-5035: TP-Link Archer c4500 Firmware
High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.
The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attacker can gain arbitrary command execution on the device with elevated privileges.This issue affects Archer C4500X: through 1_1.1.6.
Affected products
- TP-Link Archer c4500 Firmware: up to and including 1_1.1.6
- TP-Link Archer c4500x: up to and including 1_1.1.6
Published 2024-05-27. Last modified 2026-06-17.