{"id":"CVE-2022-30075","title":"In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.","summary":"In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"tp-link","product":"archer_ax50_firmware","affected":["archer_ax50_firmware <= 210730"],"published":"2022-06-09","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-30075","references":[{"url":"http://packetstormsecurity.com/files/167522/TP-Link-AX50-Remote-Code-Execution.html","label":"cve@mitre.org"},{"url":"https://github.com/aaronsvk","label":"cve@mitre.org"},{"url":"https://github.com/aaronsvk/CVE-2022-30075","label":"cve@mitre.org"},{"url":"https://www.exploit-db.com/exploits/50962","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/167522/TP-Link-AX50-Remote-Code-Execution.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://tp-link.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/aaronsvk","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/aaronsvk/CVE-2022-30075","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/50962","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.33832,"epssPercentile":0.98359,"exploitAvailable":true,"ingestedAt":"2026-07-06T17:03:24.408Z","exploits":{"exploitdb":true,"github":4,"githubRepos":["https://github.com/aaronsvk/CVE-2022-30075","https://github.com/SAJIDAMINE/CVE-2022-30075","https://github.com/M4fiaB0y/CVE-2022-30075"],"checkedAt":"2026-09-21T15:25:23.277Z"},"slug":"CVE-2022-30075","body":"## Overview\n\nIn TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.\n\n## Affected\n\n- `archer_ax50_firmware <= 210730`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":67,"depthScoreParts":{"impact":48.4,"likelihood":6.8,"exploitation":12,"ransomware":0},"changes":[]}