CVE-2023-31188
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505', Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506', and Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616'.
MĂșltiples productos TP-LINK permiten que un atacante autenticado adyacente a la red ejecute comandos arbitrarios del sistema operativo. Los productos/versiones afectados son los siguientes: versiones de firmware de Archer C50 anteriores a 'Archer C50(JP)_V3_230505', versiones de firmware de Archer C55 anteriores a 'Archer C55(JP)_V1_230506' y versiones de firmware de Archer C20 anteriores a 'Archer C20(JP) )_V1_230616'.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-08-15 CVE Reserved
- 2023-09-06 CVE Published
- 2024-09-12 EPSS Updated
- 2024-09-27 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://jvn.jp/en/vu/JVNVU99392903 | Third Party Advisory | |
https://www.tp-link.com/jp/support/download/archer-c20/v1/#Firmware | Product | |
https://www.tp-link.com/jp/support/download/archer-c50/v3/#Firmware | Product | |
https://www.tp-link.com/jp/support/download/archer-c55/#Firmware | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tp-link Search vendor "Tp-link" | Archer C55 Firmware Search vendor "Tp-link" for product "Archer C55 Firmware" | < 230506 Search vendor "Tp-link" for product "Archer C55 Firmware" and version " < 230506" | - |
Affected
| in | Tp-link Search vendor "Tp-link" | Archer C55 Search vendor "Tp-link" for product "Archer C55" | - | - |
Safe
|
Tp-link Search vendor "Tp-link" | Archer C50 V3 Firmware Search vendor "Tp-link" for product "Archer C50 V3 Firmware" | < 230505 Search vendor "Tp-link" for product "Archer C50 V3 Firmware" and version " < 230505" | - |
Affected
| in | Tp-link Search vendor "Tp-link" | Archer C50 V3 Search vendor "Tp-link" for product "Archer C50 V3" | - | - |
Safe
|