CVE-2020-10884

8.8
HIGHCVSS v3.1 Base Score
26.08%
LOW RiskEPSS (98th percentile)

This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. This issue results from the use of hard-coded encryption key. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9652.

Published: 3/25/2020
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

5.8

AV:A/AC:L/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

26.08%LOW Exploitation Risk
98th percentile

This vulnerability has a 26.08% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

CWE Classification

Advertisement