Skip to main content
Mallory
High

OS Command Injection in TP-Link Archer and Deco Routers

IdentifiersCVE-2024-21833CWE-78· Improper Neutralization of Special…

CVE-2024-21833 is an OS command injection vulnerability affecting multiple TP-Link products, including Archer and Deco series routers. According to the provided content, a network-adjacent unauthenticated attacker with access to the device can execute arbitrary operating system commands on the router. The issue is exploitable against devices in their initial configuration, where administrative login is restricted to the LAN port or Wi-Fi, indicating the attack surface is limited to local-network or wireless-adjacent access rather than arbitrary Internet-wide exposure by default. The content further states that post-exploitation tooling such as tplink_stager.sh was used after successful exploitation to identify device architecture, download payloads, and establish persistence and command-and-control on compromised routers.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows arbitrary OS command execution on the affected TP-Link device without authentication, provided the attacker has network-adjacent access. In the observed campaign described in the content, exploitation was used to deploy microsocks and a custom ShadowLink beacon, turning compromised routers into residential SOCKS5 proxies. Attackers were able to execute follow-on commands, register devices with command-and-control infrastructure, exfiltrate command output, and establish persistence through cron entries, /etc/rc.local modification, and NVRAM rc_startup changes. This can result in full compromise of the router, abuse of the device for proxying malicious traffic, long-term persistence, and potential monitoring or manipulation of traffic traversing the device.

Mitigation

If you can’t patch tonight, do this now.

Until patched, reduce exposure by restricting management access to trusted hosts and segments only, disabling unnecessary administrative services, and preventing untrusted users from reaching the router over LAN or Wi-Fi. Because the vulnerability is described as network-adjacent and unauthenticated, strong Wi-Fi security, segmentation of guest/untrusted clients, and ACLs limiting access to router management interfaces materially reduce exploitability. Monitor for anomalous outbound connections, especially to unknown infrastructure, and for signs of persistence or unauthorized proxy services on the device. If feasible, isolate vulnerable models from untrusted local users until firmware updates can be applied.

Remediation

Patch, then assume compromise.

Apply TP-Link vendor updates that address CVE-2024-21833 on all affected Archer and Deco devices. Upgrade to fixed firmware versions as specified by TP-Link for each affected model. Because the content indicates attackers used post-exploitation scripts to install persistence and additional payloads, remediation should include not only patching but also incident response validation: inspect for unauthorized cron entries, /etc/rc.local modifications, NVRAM rc_startup changes, unexpected binaries or scripts, and suspicious listening SOCKS5 services or outbound C2 traffic. If compromise is suspected, perform a factory reset, reflash with current trusted firmware, rotate administrative credentials, and review downstream network exposure.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
TP-LinkArcher Ax3000hardware
TP-LinkArcher Ax3000 Firmwareoperating_system
TP-LinkArcher Ax5400hardware
TP-LinkArcher Ax5400 Firmwareoperating_system
TP-LinkArcher Axe75application
TP-LinkArcher Axe75 Firmwareoperating_system
TP-LinkDeco X50hardware
TP-LinkDeco X50 Firmwareoperating_system
TP-LinkDeco Xe200hardware
TP-LinkDeco Xe200 Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware2

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity3

Community discussion across Reddit, Mastodon, and other social sources.