PT-2023-2913 · Tp Link · Tp-Link Tl-Wpa4530 Kit

Published

2023-03-27

·

Updated

2025-01-22

·

CVE-2023-31701

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link TL-WPA4530 KIT versions V2 (EU) 161115 through V2 (EU) 170406
Description The issue is related to Command Injection via the httpRpmPlcDeviceRemove endpoint. It is also associated with the httpRpmPlcDeviceAdd function, where the vulnerability is linked to the lack of data sanitization at the management level. This could allow a remote attacker to execute arbitrary code.
Recommendations For versions V2 (EU) 161115 through V2 (EU) 170406, consider disabling the httpRpmPlcDeviceRemove endpoint as a temporary workaround until a patch is available. Additionally, restricting access to the httpRpmPlcDeviceAdd function may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-02880
CVE-2023-31701

Affected Products

Tp-Link Tl-Wpa4530 Kit