CVE-2023-39224: OS Command Injection
Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)V2230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39224?
CVE-2023-39224 is a vulnerability in Archer C5 firmware all versions and Archer C7 firmware versions prior to Archer C7(JP)_V2_230602 that allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
Which devices are affected by CVE-2023-39224?
Archer C5 firmware all versions and Archer C7 firmware versions prior to Archer C7(JP)_V2_230602 are affected by CVE-2023-39224.
How severe is CVE-2023-39224?
CVE-2023-39224 has a severity level of high.
How can an attacker exploit CVE-2023-39224?
An attacker can exploit CVE-2023-39224 by executing arbitrary OS commands.
Is there a firmware update available to fix CVE-2023-39224?
No, there is no firmware update available to fix CVE-2023-39224 as Archer C5 is no longer supported.