CVE-2023-38568: OS Command Injection
Published Sep 6, 2023
·Updated
Archer A10 firmware versions prior to 'Archer A10(JP)V2230504' allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands.
Affected Software
2 affected components
TP-Link Archer A10 firmware<230504
TP-Link Archer A10=2.0
Event History
Sep 6, 2023
CVE Published
via MITRE·09:23 AM
Data Sourced
via MITRE·09:23 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of Archer A10 firmware?
The vulnerability ID of Archer A10 firmware is CVE-2023-38568.
2
What is the severity rating of CVE-2023-38568?
The severity rating of CVE-2023-38568 is high (8.8).
3
How does Archer A10 firmware prior to Archer A10(JP)_V2_230504 allow an attacker to execute arbitrary OS commands?
Archer A10 firmware versions prior to Archer A10(JP)_V2_230504 allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands.
4
What software versions are affected by CVE-2023-38568?
Archer A10 firmware versions prior to Archer A10(JP)_V2_230504 are affected by CVE-2023-38568.
5
How can I fix the vulnerability in Archer A10 firmware?
To fix the vulnerability in Archer A10 firmware, update to version Archer A10(JP)_V2_230504 or later.