PT-2024-2586 · Tp Link · Tp-Link Td-W9970+5
Muhammet Gedik
·
Published
2024-03-28
·
Updated
2026-05-20
·
CVE-2023-6437
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TP-Link EX20v AX1800 versions through 20240328
TP-Link Archer C5v AC1200 versions through 20240328
TP-Link TD-W9970 versions through 20240328
TP-Link TD-W9970v3 versions through 20240328
TP-Link VX220-G2u (affected versions not specified)
TP-Link VN020-G2u (affected versions not specified)
Description
The issue exists due to the lack of measures to neutralize special elements used in an operating system command, allowing for OS Command Injection. This can enable an attacker to execute arbitrary commands. The vulnerability affects various TP-Link Wi-Fi router models.
Recommendations
For TP-Link EX20v AX1800 versions through 20240328, update to a version released after 20240328.
For TP-Link Archer C5v AC1200 versions through 20240328, update to a version released after 20240328.
For TP-Link TD-W9970 versions through 20240328, update to a version released after 20240328.
For TP-Link TD-W9970v3 versions through 20240328, update to a version released after 20240328.
For TP-Link VX220-G2u and TP-Link VN020-G2u, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Archer C5V Ac1200
Tp-Link Ex20V Ax1800
Tp-Link Td-W9970
Tp-Link Td-W9970V3
Tp-Link Vn020-G2U
Tp-Link Vx220-G2U