CVE-2023-33538CISA KEVEPSS p98.5%

CVE-2023-33538TP-Link Multiple Routers Command Injection Vulnerability

TP-Link / Multiple Routers

Description

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Scoring

EPSS42.57% probability of exploitation · percentile 98.5% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2025-06-16

(incoming)1

TypeTargetConfidenceTier
KEVEntryTP-Link Multiple Routers Command Injection Vulnerabilitykev-cve-2023-335380%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
CVE
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
CVE
CVE-2026-3841
CVE
TP-Link Archer AX-21 Command Injection Vulnerability
CVE
CVE-2025-14737
CVE
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.