Lucene search

K
cvelistJpcertCVELIST:CVE-2023-37284
HistorySep 06, 2023 - 9:24 a.m.

CVE-2023-37284

2023-09-0609:24:42
jpcert
www.cve.org
archer c20
firmware
authentication
vulnerability
unauthenticated attacker
arbitrary os command
network-adjacent

9.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.0%

Improper authentication vulnerability in Archer C20 firmware versions prior to β€˜Archer C20(JP)_V1_230616’ allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication.

CNA Affected

[
  {
    "vendor": "TP-LINK",
    "product": "Archer C20",
    "versions": [
      {
        "version": "firmware versions prior to 'Archer C20(JP)_V1_230616'",
        "status": "affected"
      }
    ]
  }
]

9.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.0%

Related for CVELIST:CVE-2023-37284