CVE-2022-30075 is an authenticated remote code execution vulnerability affecting TP-Link Archer AX50 routers running firmware 210730 and earlier. The flaw is exposed through the web-based backup and restore functionality: a user with administrative access can import a crafted backup configuration file that is accepted by the device and processed without sufficient validation. Available technical details indicate that the backup can be decrypted, modified, repackaged, and restored so that attacker-controlled configuration data is written into the router’s runtime configuration. In demonstrated exploitation, the malicious backup injects a crafted DDNS service entry containing attacker-controlled script content, which is then executed by the device during configuration processing, resulting in command execution on the router.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a standalone Python exploit for authenticated remote code execution against vulnerable TP-Link routers, explicitly referencing CVE-2022-30075 and tested on the Archer AX50. The repository is minimal: a LICENSE, a README describing usage and attack flow, and a single executable script, tplink.py, which contains the exploit logic. The exploit works in several stages. First, WebClient interacts with the router's LuCI web interface over HTTP, retrieving RSA parameters from /login?form=auth and /login?form=keys, then performing an encrypted login to /login?form=login using the supplied admin password. After authentication, it downloads an encrypted configuration backup from /admin/firmware?form=config_multipart. The BackupParser class then decrypts the backup using hardcoded AES keying material embedded in the script, indicating the exploit abuses an insecure vendor backup encryption design. After decryption, the script modifies configuration content to inject an attacker-controlled command into DDNS-related settings. By default, the payload is '/usr/sbin/telnetd -l /bin/login.sh', which enables telnet access and yields a shell after the router restores the configuration and reboots. The script then re-encrypts the modified configuration and uploads it back to the same firmware/config endpoint using the restore operation. The README states that once the router comes back online, the operator can connect via telnet to obtain a root shell. Capabilities include authenticated login, encrypted request generation, backup download, backup decryption, configuration modification, backup re-encryption, malicious restore upload, and arbitrary command execution via a user-supplied -c argument. It also supports backup-only (-b) and restore-only (-r) modes. This is a real exploit rather than a detector, and because it includes a working default payload but is not part of a larger exploitation framework, OPERATIONAL is the best maturity classification.
This repository contains a single Python exploit script (tplinlk.py) targeting TP-Link routers, specifically the Archer AX50 model, exploiting CVE-2022-30075. The exploit leverages an authenticated remote code execution vulnerability via the router's configuration import/export functionality. The script automates the process of logging into the router's web interface, downloading and decrypting the configuration file, modifying it to include a malicious command (by default, launching a telnet daemon with a root shell), re-encrypting the config, and uploading it back to the router. Upon reboot, the router executes the injected command, granting the attacker root access via telnet. The script requires valid admin credentials and network access to the router's web interface. The endpoints used are the router's HTTP management URLs for authentication and configuration management. The exploit is operational, providing a working payload for remote code execution.
This repository contains a working exploit for CVE-2022-30075, an authenticated remote code execution vulnerability affecting certain TP-Link routers (notably the Archer AX50 with firmware older than June 2022). The exploit consists of a Python script ('tplink.py') and a README.md with detailed exploitation steps. The script automates the process of authenticating to the router's web interface, downloading the configuration backup, decrypting and modifying it to inject a command (by default, starting the telnet daemon), re-encrypting the modified config, and uploading it back to the router. After the router reboots and the physical LED button is pressed, the injected command is executed, enabling telnet access to the router (typically at 192.168.1.1) with root privileges. The exploit requires valid credentials for the router's web interface and targets the backup/restore functionality. The code demonstrates a full attack chain, including cryptographic operations for config file handling, and is operational for real-world exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously disclosed TP-Link router vulnerability referenced for background on backup decryption and unpacking behavior; no direct exploitation details are provided in this content.
A previously disclosed TP-Link router vulnerability referenced for background/comparison only; no substantive details are provided in this content.
An authenticated remote code execution vulnerability in TP-Link Archer AX50 firmware 210730 that allows command execution by importing a maliciously modified router configuration file.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.