Back to Database
Status published
Unknown
CVE-2024-21821
Multiple TP-LINK products allow a network-adjacent authenticated attacker with access...
Vulnerability Description
Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21821
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.tp-link.com/jp/support/download/archer-ax3000/#Firmware
- https://www.tp-link.com/jp/support/download/archer-ax5400/#Firmware
- https://www.tp-link.com/jp/support/download/archer-axe75/#Firmware
- https://www.tp-link.com/jp/support/download/archer-air-r5/v1/#Firmware
- https://jvn.jp/en/vu/JVNVU91401812/
More from TP-Link
View All →CVE-2025-40634
Stack-based buffer overflow in TP-Link Archer AX50
Critical
9.2
CVE-2025-3442
Information Disclosure Vulnerability in TP-Link Tapo IoT Smart Hub
Medium
4.4
CVE-2025-1099
Information Disclosure Vulnerability in TP-Link Tapo C500 Wi-Fi Camera
High
7
CVE-2025-0730
TP-Link TL-SG108E HTTP GET Request usr_account_set.cgi get request method with sensitive query strings
Medium
6.3
CVE-2025-0729
TP-Link TL-SG108E clickjacking
Medium
6.9
Affected Vendor
TP-Link
View all reports →Affected Software
Archer AX3000, Archer AX5400, Archer AXE75, Archer Air R5
Vulnerable Versions:
firmware versions prior to "Archer AX3000(JP)_V1_1.1.2 Build 20231115", firmware versions prior to "Archer AX5400(JP)_V1_1.1.2 Build 20231115", firmware versions prior to "Archer AXE75(JP)_V1_231115", firmware versions prior to "Archer Air R5(JP)_V1_1.1.6 Build 20240508"
Timeline
Official Publish:
January 10th, 2024
Last Modified:
June 17th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.