CVSS v3
7.2
HIGH
EPSS Score
19.6%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.
TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.
Active exploitation of CVE-2018-19537 has not been confirmed. The EPSS score is 19.6%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2018-19537 has a CVSS v3 base score of 7.2 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).