PT-2023-5597 · Tp Link · Archer Ax50+2

CVE-2023-40357

·

Publicado

2023-09-06

·

Atualizado

2024-09-27

CVSS v3.1

8.0

Alta

VetorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Archer AX50 versions prior to Archer AX50(JP) V1 230529 Archer A10 versions prior to Archer A10(JP) V2 230504 Archer AX10 versions prior to Archer AX10(JP) V1.2 230508 Archer AX11000 versions prior to Archer AX11000(JP) V1 230523
Description Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. The issue exists due to the lack of measures to neutralize special elements used in the operating system command. Exploitation of the issue may allow a remote attacker to execute arbitrary commands in the operating system.
Recommendations For Archer AX50 versions prior to Archer AX50(JP) V1 230529, update the firmware to Archer AX50(JP) V1 230529 or later. For Archer A10 versions prior to Archer A10(JP) V2 230504, update the firmware to Archer A10(JP) V2 230504 or later. For Archer AX10 versions prior to Archer AX10(JP) V1.2 230508, update the firmware to Archer AX10(JP) V1.2 230508 or later. For Archer AX11000 versions prior to Archer AX11000(JP) V1 230523, update the firmware to Archer AX11000(JP) V1 230523 or later.

Correção

Memory Corruption

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06252
CVE-2023-40357

Produtos afetados

Archer A10
Archer Ax11000
Archer Ax50