An issue in the firmware update process of TP-LINK TL-WA801N / TL-WA801ND V1 v3.12.16 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
https://github.com/Live-Hack-CVE/CVE-2022-46914
https://www.tp-link.com/us/press/security-advisory/