An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow …
高危 CVSS 8.0
摘要
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in natur…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://www.tp-link.com/en/support/download/archer-be230/v1.20/#Firmware Product
- https://www.tp-link.com/en/support/download/archer-be3600/v1/#Firmware
- https://www.tp-link.com/kr/support/download/archer-be3600/v1/#Firmware
- https://www.tp-link.com/sg/support/download/archer-be230/v1.20/#Firmware Product
- https://www.tp-link.com/us/support/download/archer-be230/v1.20/#Firmware Product
- https://www.tp-link.com/us/support/download/archer-be3600/v1.26/#Firmware
- https://www.tp-link.com/us/support/faq/4935/ Patch
时间线
- nvd_ingest NVD