CVE-2023-39224
CVE-2023-39224 is a high-severity vulnerability in Tp-link Archer C7 Firmware with a CVSS 3.x base score of 8.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: High (CVSS 3.x base score 8.0)
- EPSS exploit prediction: 0% (32nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-78
- Affected product: Tp-link Archer C7 Firmware
- Published:
- Last modified:
Description
Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.
Frequently asked questions
- What is CVE-2023-39224?
- Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.
- How severe is CVE-2023-39224?
- CVE-2023-39224 has a CVSS 3.x base score of 8.0, rated high severity. It is exploitable over an adjacent network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-39224 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (32nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-39224?
- CVE-2023-39224 affects Tp-link Archer C7 Firmware. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-39224?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2023-39224 published?
- CVE-2023-39224 was published on 2023-09-06 and last updated on 2026-06-17.
References
- https://jvn.jp/en/vu/JVNVU99392903/
- https://www.tp-link.com/jp/support/download/archer-c7/v2/#Firmware
Affected products (1)
- cpe:2.3:o:tp-link:archer_c7_firmware:*:*:*:*:*:*:*:*
More vulnerabilities in Tp-link Archer C7 Firmware
- CVE-2020-35575 — Critical (CVSS 9.8): A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full…
- CVE-2026-5363 — High (CVSS 8.8): Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery…
- CVE-2015-3035 — High (CVSS 7.5): Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before…
- CVE-2025-9377 — High (CVSS 7.2): The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer…
- CVE-2023-50224 — Medium (CVSS 6.5): TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows…
- CVE-2023-2646 — Medium (CVSS 4.5): A vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this…
All CVEs affecting Tp-link Archer C7 Firmware →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-100382 — Critical (CVSS 10.0): Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia…
- CVE-2026-77521 — Critical (CVSS 10.0): MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool,…
- CVE-2026-82004 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76197 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76195 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…