CVE-2023-31188: OS Command Injection
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer C50 firmware versions prior to 'Archer C50(JP)V3230505', Archer C55 firmware versions prior to 'Archer C55(JP)V1230506', and Archer C20 firmware versions prior to 'Archer C20(JP)V1230616'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31188?
The severity of CVE-2023-31188 is high.
Which TP-LINK products are affected by CVE-2023-31188?
The TP-LINK products affected by CVE-2023-31188 include Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505', Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506', and Archer C20 firmware versions.
How can an attacker exploit CVE-2023-31188?
An authenticated attacker who is network-adjacent can exploit CVE-2023-31188 to execute arbitrary OS commands.
Where can I find more information about CVE-2023-31188?
You can find more information about CVE-2023-31188 at the following references: [Reference 1](https://jvn.jp/en/vu/JVNVU99392903/), [Reference 2](https://www.tp-link.com/jp/support/download/archer-c20/v1/#Firmware), [Reference 3](https://www.tp-link.com/jp/support/download/archer-c50/v3/#Firmware).
What is the Common Weakness Enumeration (CWE) for CVE-2023-31188?
The Common Weakness Enumeration (CWE) for CVE-2023-31188 is CWE-78.