Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-49134


A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build 20220216. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.This vulnerability impacts `uclited` on the EAP115(V4) 5.0.4 Build 20220216 of the N300 Wireless Gigabit Access Point.


Published

2024-04-09T15:15:29.220

Last Modified

2025-08-21T17:59:11.630

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-829
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link eap225_firmware 5.1.0 Yes
Hardware tp-link eap225 v3 No
Operating System tp-link eap115_firmware 5.0.4 Yes
Hardware tp-link eap115 v4 No

References