PT-2023-5597 · Tp Link · Archer Ax50+2

Published

2023-09-06

·

Updated

2024-09-27

·

CVE-2023-40357

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Archer AX50 versions prior to Archer AX50(JP) V1 230529 Archer A10 versions prior to Archer A10(JP) V2 230504 Archer AX10 versions prior to Archer AX10(JP) V1.2 230508 Archer AX11000 versions prior to Archer AX11000(JP) V1 230523
Description Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. The issue exists due to the lack of measures to neutralize special elements used in the operating system command. Exploitation of the issue may allow a remote attacker to execute arbitrary commands in the operating system.
Recommendations For Archer AX50 versions prior to Archer AX50(JP) V1 230529, update the firmware to Archer AX50(JP) V1 230529 or later. For Archer A10 versions prior to Archer A10(JP) V2 230504, update the firmware to Archer A10(JP) V2 230504 or later. For Archer AX10 versions prior to Archer AX10(JP) V1.2 230508, update the firmware to Archer AX10(JP) V1.2 230508 or later. For Archer AX11000 versions prior to Archer AX11000(JP) V1 230523, update the firmware to Archer AX11000(JP) V1 230523 or later.

Fix

Memory Corruption

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-06252
CVE-2023-40357

Affected Products

Archer A10
Archer Ax11000
Archer Ax50