CVE-2023-40357
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'.
MĂșltiples productos TP-LINK permiten que un atacante autenticado adyacente a la red ejecute comandos arbitrarios del sistema operativo. Los productos/versiones afectados son los siguientes: Versiones de firmware de Archer AX50 anteriores a 'Archer AX50(JP)_V1_230529', Versiones de firmware de Archer A10 anteriores a 'Archer A10(JP)_V2_230504', Versiones de firmware de Archer AX10 anteriores a 'Archer AX10(JP) _V1.2_230508' y versiones de firmware de Archer AX11000 anteriores a 'Archer AX11000(JP)_V1_230523'.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-08-15 CVE Reserved
- 2023-09-06 CVE Published
- 2024-09-12 EPSS Updated
- 2024-09-27 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (5)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tp-link Search vendor "Tp-link" | Archer Ax50 Firmware Search vendor "Tp-link" for product "Archer Ax50 Firmware" | < 230529 Search vendor "Tp-link" for product "Archer Ax50 Firmware" and version " < 230529" | - |
Affected
| in | Tp-link Search vendor "Tp-link" | Archer Ax50 Search vendor "Tp-link" for product "Archer Ax50" | 1.0 Search vendor "Tp-link" for product "Archer Ax50" and version "1.0" | - |
Safe
|
Tp-link Search vendor "Tp-link" | Archer A10 Firmware Search vendor "Tp-link" for product "Archer A10 Firmware" | <= 230504 Search vendor "Tp-link" for product "Archer A10 Firmware" and version " <= 230504" | - |
Affected
| in | Tp-link Search vendor "Tp-link" | Archer A10 Search vendor "Tp-link" for product "Archer A10" | - | - |
Safe
|
Tp-link Search vendor "Tp-link" | Archer Ax10 Firmware Search vendor "Tp-link" for product "Archer Ax10 Firmware" | < 230508 Search vendor "Tp-link" for product "Archer Ax10 Firmware" and version " < 230508" | - |
Affected
| in | Tp-link Search vendor "Tp-link" | Archer Ax10 Search vendor "Tp-link" for product "Archer Ax10" | - | - |
Safe
|
Tp-link Search vendor "Tp-link" | Archer Ax11000 Firmware Search vendor "Tp-link" for product "Archer Ax11000 Firmware" | < 230523 Search vendor "Tp-link" for product "Archer Ax11000 Firmware" and version " < 230523" | - |
Affected
| in | Tp-link Search vendor "Tp-link" | Archer Ax11000 Search vendor "Tp-link" for product "Archer Ax11000" | - | - |
Safe
|