CVE-2022-30075
62Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 34%
from disclosure to weapon0 days
Published on NVDJun 9
1st PoCJun 7
VulnCheck+901d
exploitation probability
34%top 2% of all CVEs
observed exploitation
yesVulnCheck
10 public exploit(s)
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.
Affected products
n/a · n/apublic PoCs found — 10
cve_referencewww.exploit-db.com/exploits/50962unverifiedgithubgithub.com/aaronsvk/CVE-2022-30075★ 235githubgithub.com/SAJIDAMINE/CVE-2022-30075★ 3githubgithub.com/M4fiaB0y/CVE-2022-30075★ 1githubgithub.com/RhestCorp/TP-L-NK-SIZMA-EXPLO-T★ 1vulncheckvulncheck.com/xdb/37e9dfd2edf1unverifiedcve_referencepacketstormsecurity.com/files/167522/TP-Link-AX50-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/b9fd6e2d6f15unverifiedvulncheckvulncheck.com/xdb/941952aea6f9unverifiedvulncheckvulncheck.com/xdb/18b79bacc0f5unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.