CVE-2023-43138

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
20/09/2023
Last modified:
22/09/2023

Description

TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:tl-er5120g_firmware:2.0.0:build_210817:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-er5120g:4.0:*:*:*:*:*:*:*