STAR Labs detailed exploitation of CVE-2020-10882, an unauthenticated remote code execution flaw in TP-Link Archer A7 AC1750 routers and related Archer C7 firmware. The bug affects the tdpServer service listening on UDP port 20002, where the slave_mac value from an encrypted JSON message is insufficiently validated before being passed to system(), allowing a network-adjacent attacker to execute commands as root. The researchers said the issue was also used at Pwn2Own 2019.
The writeup shows how reverse engineering and bindiffing of vulnerable and patched firmware exposed the vulnerable code path and reconstructed TP-Link's proprietary TDP protocol, including its 16-byte header, checksum validation, and AES-CBC payload encryption using hardcoded key and IV material. By crafting a slave_key_offer message with specific header values and a malicious slave_mac, an attacker can bypass authentication and trigger command injection; despite a short input-length limit, the exploit can assemble commands across multiple packets, execute a script, and obtain a shell, including altering web content hosted on the router.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
STAR Labs published a detailed write-up analyzing CVE-2020-10882, including reverse engineering of the TDP protocol, identification of the vulnerable tdpServer code path, and reconstruction of packet encryption and checksum handling. The post also released proof-of-concept exploitation details showing remote shell access and arbitrary modification of router web content.
CVE-2020-10882, an unauthenticated remote code execution flaw in the TP-Link Archer A7/related Archer C7 firmware, was used during Pwn2Own 2019. The bug was in the tdpServer service on UDP port 20002, where the slave_mac field could be abused for command injection leading to root-level code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.