Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'.

Project Subscriptions

Vendors Products
Tp-link Subscribe
Archer A10 Subscribe
Archer A10 Firmware Subscribe
Archer Ax10 Subscribe
Archer Ax10 Firmware Subscribe
Archer Ax11000 Subscribe
Archer Ax11000 Firmware Subscribe
Archer Ax50 Subscribe
Archer Ax50 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-44928 Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 27 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:tp-link:archer_a10_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_ax10_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_ax11000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_ax50_firmware:-:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-09-27T20:07:01.652Z

Reserved: 2023-08-15T07:33:34.791Z

Link: CVE-2023-40357

cve-icon Vulnrichment

Updated: 2024-08-02T18:31:53.663Z

cve-icon NVD

Status : Modified

Published: 2023-09-06T10:15:14.820

Modified: 2024-11-21T08:19:17.597

Link: CVE-2023-40357

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses