← back
CVE-2024-57040criticalobserved exploitationCWE-798

CVE-2024-57040

70Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.8epss 1.1%
from disclosure to weapon20 days
Published on NVDFeb 26
1st PoC+20d
VulnCheck+328d
exploitation probability
1.1%top 35% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained by analyzing downloaded firmware or via a brute force attack through physical access to the router. NOTE: The supplier has stated that this issue was fixed in firmware versions 250401 or later.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.