Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-31756


A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1.0. 0.9.1 v5006.0 Build 220518 Rel.32480n which allows remote attackers, authenticated to the administrative web portal as an administrator user to open an operating system level shell via the 'X_TP_IfName' parameter.


Published

2023-05-19T13:15:08.877

Last Modified

2025-01-21T18:15:14.010

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-78
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link archer_vr1600v_firmware ≤ 0.1.0_0.9.1_v5006.0_build_200810_rel.53181n Yes
Hardware tp-link archer_vr1600v - No

References