Show filters
169 Total Results
Displaying 21-30 of 169
Sort by:
Attacker Value
Unknown

CVE-2024-21773

Disclosure Date: January 11, 2024 (last updated July 04, 2024)
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.
Attacker Value
Unknown

CVE-2023-48642

Disclosure Date: December 12, 2023 (last updated December 15, 2023)
Archer Platform 6.x before 6.13 P2 (6.13.0.2) contains an authenticated HTML content injection vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release.
Attacker Value
Unknown

CVE-2023-48641

Disclosure Date: December 12, 2023 (last updated December 16, 2023)
Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating application resource references in user requests to bypass authorization checks, in order to gain execute access to AWF application resources.
Attacker Value
Unknown

CVE-2023-48053

Disclosure Date: November 16, 2023 (last updated November 22, 2023)
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
Attacker Value
Unknown

CVE-2023-45358

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release.
Attacker Value
Unknown

CVE-2023-45357

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release.
Attacker Value
Unknown

CVE-2023-40531

Disclosure Date: September 06, 2023 (last updated October 08, 2023)
Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
Attacker Value
Unknown

CVE-2023-40357

Disclosure Date: September 06, 2023 (last updated October 08, 2023)
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'.
Attacker Value
Unknown

CVE-2023-39935

Disclosure Date: September 06, 2023 (last updated October 08, 2023)
Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.
Attacker Value
Unknown

CVE-2023-39224

Disclosure Date: September 06, 2023 (last updated October 08, 2023)
Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.