PT-2023-2913 · Tp Link · Tp-Link Tl-Wpa4530 Kit
Published
2023-03-27
·
Updated
2025-01-22
·
CVE-2023-31701
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link TL-WPA4530 KIT versions V2 (EU) 161115 through V2 (EU) 170406
Description
The issue is related to Command Injection via the
httpRpmPlcDeviceRemove endpoint. It is also associated with the httpRpmPlcDeviceAdd function, where the vulnerability is linked to the lack of data sanitization at the management level. This could allow a remote attacker to execute arbitrary code.Recommendations
For versions V2 (EU) 161115 through V2 (EU) 170406, consider disabling the
httpRpmPlcDeviceRemove endpoint as a temporary workaround until a patch is available. Additionally, restricting access to the httpRpmPlcDeviceAdd function may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Tl-Wpa4530 Kit