LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-33538: TP-Link Multiple Routers Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 16, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 7, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-33538 to its Known Exploited Vulnerabilities catalog on Jun 16, 2025, with a federal patch deadline of Jul 7, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL)…

CVE-2023-33538 is a command injection vulnerability affecting certain TP-Link routers, specifically models TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2. It involves the /userRpm/WlanNetworkRpm component and allows an attacker to inject and execute commands on the device. These products may be end-of-life or end-of-service, which raises the risk that unpatched units remain exposed on networks. For IT and security teams, this matters because compromised routers can serve as entry points for further network access, traffic interception, or lateral movement.

Public detail is limited to the models and component named above; teams should confirm all specifics against the vendor advisory and CISA guidance before acting.

How it works

The flaw is classified as CWE-77, improper neutralization of special elements used in a command. In this class of weakness, input that reaches a command interpreter is not properly sanitized, so an attacker can append or substitute shell commands. On the affected TP-Link devices the injection point is the /userRpm/WlanNetworkRpm component. An attacker who can reach that interface—typically via the web management path—can supply crafted input that the device executes with the privileges of the router process. Exact request format, authentication requirements, and payload details are not provided in the available facts and must be verified against the vendor advisory. Successful abuse can yield arbitrary command execution on the router itself, potentially allowing configuration changes, credential theft, or use of the device as a pivot.

Am I affected? How to find it in your systems

These devices are consumer and small-office wireless routers commonly found at the network edge or in branch locations. Inventory starts with asset management records, DHCP leases, and network discovery scans that identify TP-Link hardware by MAC OUI, hostname, or HTTP banner. Check the model and hardware version printed on the device label or shown in the administration interface against the list TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2. Firmware version strings should also be recorded and compared with the vendor advisory, because the facts note that the products may already be end-of-life or end-of-service.

Telemetry signs of exploitation are limited in public detail. Look for unexpected process activity, configuration changes, or outbound connections originating from the router’s management IP. Web-server access logs that show requests to /userRpm/WlanNetworkRpm with anomalous parameters may indicate probing; confirm expected log formats against the device documentation. Because the products can be EoL/EoS, any unit still in production should be treated as potentially vulnerable until proven otherwise.

How to remediate

The primary action is to apply mitigations per vendor instructions. CISA further advises following applicable BOD 22-01 guidance for cloud services or discontinuing use of the product if mitigations are unavailable. Given the end-of-life/end-of-service status noted for the impacted models, the recommended long-term remediation is often replacement with a supported device rather than continued reliance on patches that may no longer be issued. After any firmware update, re-verify the version string and re-harden the management interface (disable remote administration, change default credentials, restrict access by source IP). Document the change and re-scan the network to confirm the old units are no longer reachable.

If you can't patch immediately

Until a supported replacement or vendor-approved mitigation is in place, reduce exposure with compensating controls. Segment the router so that its management interface is reachable only from a dedicated, authenticated jump host or management VLAN; block all other inbound access at the upstream firewall. If a web application firewall or IPS is available, apply virtual-patching rules that inspect and drop requests containing command-injection patterns aimed at /userRpm/WlanNetworkRpm—test rules carefully to avoid breaking legitimate WLAN configuration. Disable any unused wireless or remote-management features that rely on the vulnerable component. Increase monitoring: alert on configuration changes, new administrative sessions, and unusual DNS or outbound traffic from the router. These steps lower risk but do not eliminate it; plan for full remediation or decommissioning as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches in which credentials, configuration data, or traffic traversing the router are collected. Known ransomware use of this CVE is not documented. If compromise is suspected, isolate the device, preserve logs, and examine any systems that authenticated through or stored credentials on the router. Readers can run a free exposure scan of their email addresses to check whether those addresses appear in known breach data sets and then rotate any reused passwords.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTP-Link · Multiple Routers
WeaknessCWE-77
Added to CISA KEVJun 16, 2025
Federal patch deadlineJul 7, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities