The TP-Link Archer C5400X gaming router contains a maximum-severity security issue that, when sent with specially crafted requests, might allow remote code execution on vulnerable devices.
The vulnerability has a 10.0 CVSS score and is tagged as CVE-2024-5035. It affects the router firmware in all versions, including 1.1.6. On May 24, 2024, version 1_1.1.7 was released with a patch.
In a report released on Monday, German cybersecurity company ONEKEY stated that “remote unauthenticated attackers can gain arbitrary command execution on the device with elevated privileges by successfully exploiting this flaw.”
The problem stems from a radio frequency testing binary called “rftest” that launches at startup and opens TCP ports to network listeners read more TP-Link Gaming Router Vulnerability Exposes Users to Remote Code Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
