HIGH🇵🇱 Wersja polska

CVE-2023-39224

CVSS 8.0v3.1pub. 2023-09-06upd. 2024-11-21

Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Tp Link Archer C7

    HW
    Tp-Link
    2.0
  • Tp Link Archer C7 Firmware

    OS
    Tp-Link
    < 230602
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2020-35575CRITICAL9.8PL ✓same product

Ujawnienie hasła przez interfejs web w urządzeniach TP-Link

CVE-2025-9377HIGH8.6⚠ KEVsame product

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link...

CVE-2015-3035HIGH7.5⚠ KEVsame product

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmwa...

CVE-2023-50224MEDIUM6.5⚠ KEVsame product

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability...

CVE-2026-5363MEDIUM5.4same product

Podatność Inadequate Encryption Strength w TP-Link Archer C7 v5 i v5.8 (moduły uhttpd) umożliwia wyzyskanie od...