CVE-2023-31756

CVSS V2 None CVSS V3 None
Description
A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1.0. 0.9.1 v5006.0 Build 220518 Rel.32480n which allows remote attackers, authenticated to the administrative web portal as an administrator user to open an operating system level shell via the 'X_TP_IfName' parameter.
Overview
  • CVE ID
  • CVE-2023-31756
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-05-19T13:15:08
  • Last Modified Date
  • 2023-05-19T13:15:08
References
History
Created Old Value New Value Data Type Notes
2023-05-19 14:00:52 Added to TrackCVE