CVE-2024-5244Exploit(tp-link / omada_er605)

LOWCVSS 4.2 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent attackers to access or spoof DDNS messages on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are vulnerable only if configured to use the Comexe DDNS service. The specific flaw exists within the cmxddnsd executable. The issue results from reliance on obscurity to secure network data. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-22439.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-656

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • omada_er605
  • omada_er605_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Exploit: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
omada_er605omada_er605_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-08: 1PoC Mentioned / Linked · 2026-02-08: 102-08
Signal classification1 categories
Exploit
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Blackstorm Security@blackstormsecbr
    Exploit

    TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244: https://oobs.io/posts/er605-1day-exploit/ #exploit #vulnerability #rce #informationsecurity #cybersecurity #infosec https://t.co/RulxemI2kQ

    Post summary

    The tweet announces a pre‑authentication RCE chain on TP‑Link ER605, links to a post likely containing a PoC, and emphasizes the availability of an exploit.

    0502891.3K
    1.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkomada_er6052.6--
OStp-linkomada_er605_firmware2.2.2--

Explore more