TP-Link TL-WPA8630 V2.2.4 Build 20230427 Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the TP-Link TL-WPA8630 (US) version V2.2.4 Build 20230427. The issue arises from a command injection vulnerability in the function sub_4256CC, which allows attackers to execute arbitrary code by injecting specific commands.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected device.

Reproduction

To reproduce this vulnerability, send a command injection payload that includes the 'devpwd' parameter to the vulnerable device running TP-Link TL-WPA8630 V2.2.4 Build 20230427. The injected command will be executed on the device, leading to remote code execution.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.6
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.