Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'.
2023-09-06T10:15:14.820
2024-11-21T08:19:17.597
Modified
CVSSv3.1: 8.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tp-link | archer_ax50_firmware | < 230529 | Yes |
Hardware | tp-link | archer_ax50 | 1.0 | No |
Operating System | tp-link | archer_a10_firmware | ≤ 230504 | Yes |
Hardware | tp-link | archer_a10 | - | No |
Operating System | tp-link | archer_ax10_firmware | < 230508 | Yes |
Hardware | tp-link | archer_ax10 | - | No |
Operating System | tp-link | archer_ax11000_firmware | < 230523 | Yes |
Hardware | tp-link | archer_ax11000 | - | No |