« Volver al listado

CVE-2024-21773

Estado: ModificadaAlta (8.8)—

Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-21773",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-21773",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-08T17:31:06.091432Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "TP-Link",
          "product": "Archer AX3000",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to \"Archer AX3000(JP)_V1_1.1.2 Build 20231115\""
            }
          ]
        },
        {
          "vendor": "TP-Link",
          "product": "Archer AX5400",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to \"Archer AX5400(JP)_V1_1.1.2 Build 20231115\""
            }
          ]
        },
        {
          "vendor": "TP-Link",
          "product": "Deco X50",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to \"Deco X50(JP)_V1_1.4.1 Build 20231122\""
            }
          ]
        },
        {
          "vendor": "TP-Link",
          "product": "Deco XE200",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to \"Deco XE200(JP)_V1_1.2.5 Build 20231120\""
            }
          ]
        },
        {
          "vendor": "TP-Link",
          "product": "Archer Air R5",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to \"Archer Air R5(JP)_V1_1.1.6 Build 20240508\""
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-01-11T00:15:44.560",
  "references": [
    {
      "url": "https://jvn.jp/en/vu/JVNVU91401812/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/archer-air-r5/v1/#Firmware",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/archer-ax3000/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/archer-ax5400/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/deco-x50/v1/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/deco-xe200/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/vu/JVNVU91401812/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/archer-air-r5/v1/#Firmware",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/archer-ax3000/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/archer-ax5400/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/deco-x50/v1/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tp-link.com/jp/support/download/deco-xe200/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings."
    },
    {
      "lang": "es",
      "value": "Múltiples productos TP-LINK permiten que un atacante no autenticado adyacente a la red con acceso al producto ejecute comandos arbitrarios del sistema operativo. Los productos/versiones afectados son los siguientes: Versiones de firmware Archer AX3000 anteriores a \"Archer AX3000(JP)_V1_1.1.2 Build 20231115\", Versiones de firmware Archer AX5400 anteriores a \"Archer AX5400(JP)_V1_1.1.2 Build 20231115\", Versiones de firmware Deco X50 anteriores a \"Deco X50(JP)_V1_1.4.1 Build 20231122\" y versiones de firmware Deco XE200 anteriores a \"Deco XE200(JP)_V1_1.2.5 Build 20231120\"."
    }
  ],
  "lastModified": "2026-06-17T07:10:08.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_ax3000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E511835-B9F8-48F6-85D0-92BD9EF6B93C",
              "versionEndExcluding": "1.1.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_ax3000:1.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "60E38020-7C23-4B8E-B04C-DCC67A386004"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_ax5400_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "116BFAEE-8C19-4101-9754-CD55C951AA34",
              "versionEndExcluding": "1.1.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_ax5400:1.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "76D439C9-D0A9-40C5-A91A-3FE205A0139D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:deco_x50_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49F92855-4C16-4785-BCB0-DF648574AE5B",
              "versionEndExcluding": "1.4.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:deco_x50:1.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B07192F7-E04C-43BA-9452-B970EF8796A7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:deco_xe200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E38052E-2386-4DE1-9E3C-E6C39B2720A8",
              "versionEndExcluding": "1.2.5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:deco_xe200:1.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "92D840AF-F273-4B48-B8A2-4081E3D484A6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}