logo

TP-Link fixes critical RCE bug in popular C5400X gaming router

ID: 415c8f0e-7796-5c38-bee0-d56fcc12a1c9

STIX ID: report--415c8f0e-7796-5c38-bee0-d56fcc12a1c9

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The TP‑Link Archer C5400X contains a critical remote command injection and buffer overflow vulnerability in the 'rftest' network service (CVE-2024-5035, CVSS 10.0) reachable on TCP ports 8888–8890; an attacker can supply shell metacharacters to achieve elevated arbitrary command execution. TP‑Link released firmware v1.1.7 (Build 20240510) on May 24, 2024 to filter out shell metacharacters and remediate the issue; users should update vulnerable devices promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.