PT-2024-2586 · Tp Link · Tp-Link Td-W9970+5

Muhammet Gedik

·

Published

2024-03-28

·

Updated

2026-05-20

·

CVE-2023-6437

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TP-Link EX20v AX1800 versions through 20240328 TP-Link Archer C5v AC1200 versions through 20240328 TP-Link TD-W9970 versions through 20240328 TP-Link TD-W9970v3 versions through 20240328 TP-Link VX220-G2u (affected versions not specified) TP-Link VN020-G2u (affected versions not specified)
Description The issue exists due to the lack of measures to neutralize special elements used in an operating system command, allowing for OS Command Injection. This can enable an attacker to execute arbitrary commands. The vulnerability affects various TP-Link Wi-Fi router models.
Recommendations For TP-Link EX20v AX1800 versions through 20240328, update to a version released after 20240328. For TP-Link Archer C5v AC1200 versions through 20240328, update to a version released after 20240328. For TP-Link TD-W9970 versions through 20240328, update to a version released after 20240328. For TP-Link TD-W9970v3 versions through 20240328, update to a version released after 20240328. For TP-Link VX220-G2u and TP-Link VN020-G2u, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-02646
CVE-2023-6437

Affected Products

Tp-Link Archer C5V Ac1200
Tp-Link Ex20V Ax1800
Tp-Link Td-W9970
Tp-Link Td-W9970V3
Tp-Link Vn020-G2U
Tp-Link Vx220-G2U