Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-40357


Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'.


Published

2023-09-06T10:15:14.820

Last Modified

2024-11-21T08:19:17.597

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-78
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link archer_ax50_firmware < 230529 Yes
Hardware tp-link archer_ax50 1.0 No
Operating System tp-link archer_a10_firmware ≤ 230504 Yes
Hardware tp-link archer_a10 - No
Operating System tp-link archer_ax10_firmware < 230508 Yes
Hardware tp-link archer_ax10 - No
Operating System tp-link archer_ax11000_firmware < 230523 Yes
Hardware tp-link archer_ax11000 - No

References