8

CVE-2023-40357

Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Archer Ax50 Firmware Version < 230529
   Tp-link ≫ Archer Ax50 Version 1.0
Tp-link ≫ Archer A10 Firmware Version <= 230504
   Tp-link ≫ Archer A10 Version -
Tp-link ≫ Archer Ax10 Firmware Version < 230508
   Tp-link ≫ Archer Ax10 Version -
Tp-link ≫ Archer Ax11000 Firmware Version < 230523
   Tp-link ≫ Archer Ax11000 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.333
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://jvn.jp/en/vu/JVNVU99392903/
Third Party Advisory
https://www.tp-link.com/jp/support/download/archer-a10/#Firmware
Product
https://www.tp-link.com/jp/support/download/archer-ax10/#Firmware
Product
https://www.tp-link.com/jp/support/download/archer-ax11000/#Firmware
Product
https://www.tp-link.com/jp/support/download/archer-ax50/#Firmware
Product