CVE-2023-36489: OS Command Injection
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)V4221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)V14230506', and TL-WR902AC firmware versions prior to 'TL-WR902AC(JP)V3230506'.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this TP-LINK product vulnerability?
The vulnerability ID for this TP-LINK product vulnerability is CVE-2023-36489.
What is the severity of CVE-2023-36489?
The severity of CVE-2023-36489 is high with a CVSS score of 8.8.
Which TP-LINK products are affected by CVE-2023-36489?
The TP-LINK products affected by CVE-2023-36489 are TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)_V14_230506', and TL-WR902AC firmware versions up to 230506.
How can an attacker exploit CVE-2023-36489?
An unauthenticated attacker who is network-adjacent can exploit CVE-2023-36489 by executing arbitrary OS commands.
Are TP-LINK TL-WR902AC, TL-WR802N, and TL-WR841N devices vulnerable to CVE-2023-36489?
Yes, TP-LINK TL-WR902AC, TL-WR802N, and TL-WR841N devices are vulnerable to CVE-2023-36489 if they are running the firmware versions mentioned.