CVE-2023-40357: OS Command Injection
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)V1230529', Archer A10 firmware versions prior to 'Archer A10(JP)V2230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)V1.2230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)V1230523'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40357?
The severity of CVE-2023-40357 is high with a severity value of 8.
Which TP-LINK products are affected by CVE-2023-40357?
The TP-LINK products affected by CVE-2023-40357 are Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', and Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1_230508'.
How can an attacker exploit CVE-2023-40357?
An attacker can exploit CVE-2023-40357 by being network-adjacent and authenticated, allowing them to execute arbitrary OS commands.
Where can I find more information about CVE-2023-40357?
You can find more information about CVE-2023-40357 at the following references: [1] https://jvn.jp/en/vu/JVNVU99392903/ [2] https://www.tp-link.com/jp/support/download/archer-a10/#Firmware [3] https://www.tp-link.com/jp/support/download/archer-ax10/#Firmware
How do I fix CVE-2023-40357?
To fix CVE-2023-40357, update your TP-LINK product to the latest firmware versions listed in the references: Archer AX50 firmware 'Archer AX50(JP)_V1_230529', Archer A10 firmware 'Archer A10(JP)_V2_230504', and Archer AX10 firmware 'Archer AX10(JP)_V1_230508'.