High severity8.8CISA KEVNVD Advisory· Published Jun 7, 2023· Updated Jun 17, 2026
CVE-2023-33538
CVE-2023-33538
Description
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:o:tp-link:tl-wr740n_firmware:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:tp-link:tl-wr740n_firmware:-:*:*:*:*:*:*:*
- (no CPE)range: V1/V2
- cpe:2.3:o:tp-link:tl-wr940n_firmware:-:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: V2/V4
Patches
Vulnerability mechanics
References
5- github.com/a101e-IoTvul/iotvul/blob/main/tp-link/3/TL-WR940N_TL-WR841N_userRpm_WlanNetworkRpm_Command_Injection.mdnvdBroken LinkExploitThird Party Advisory
- web.archive.org/web/20230609111043/https://github.com/a101e-IoTvul/iotvul/blob/main/tp-link/3/TL-WR940N_TL-WR841N_userRpm_WlanNetworkRpm_Command_Injection.mdnvdExploitThird Party Advisory
- www.secpod.com/blog/cisa-issues-warning-on-active-exploitation-of-tp-link-vulnerability-cve-2023-33538/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.tp-link.com/us/support/faq/3562/nvdProduct
News mentions
1- A Deep Dive Into Attempted Exploitation of CVE-2023-33538Unit 42 · Apr 16, 2026