CVE-2023-31198
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2023-31198 is a critical OS command injection vulnerability discovered in certain Wi-Fi Access Points (APs) from TP-Link. Affected models include AC-PD-WAPU, AC-PD-WAPUM, AC-PD-WAPU-P, AC-PD-WAPUM-P, AC-WAPU-300, AC-WAPUM-300, AC-WAPU-300-P, and AC-WAPUM-300-P, with versions prior to 1.05_B08 being vulnerable. This issue allows a remote, authenticated attacker with administrative privileges to execute arbitrary OS commands. If exploited, the attacker could gain unauthorized access, install malware, or cause significant damage to the affected network. System administrators are strongly urged to update their devices to the latest firmware version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- INABA