ID

VAR-202309-1787


CVE

CVE-2023-43138


TITLE

TP-LINK Technologies  of  TL-ER5120G  Command injection vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2023-012826

DESCRIPTION

TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point. TP-LINK Technologies of TL-ER5120G Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2023-43138 // JVNDB: JVNDB-2023-012826

AFFECTED PRODUCTS

vendor:tp linkmodel:tl-er5120gscope:eqversion:2.0.0

Trust: 1.0

vendor:tp linkmodel:tl-er5120gscope:eqversion: -

Trust: 0.8

vendor:tp linkmodel:tl-er5120gscope:eqversion:tl-er5120g firmware 2.0.0

Trust: 0.8

vendor:tp linkmodel:tl-er5120gscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2023-012826 // NVD: CVE-2023-43138

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-43138
value: HIGH

Trust: 1.0

NVD: CVE-2023-43138
value: HIGH

Trust: 0.8

nvd@nist.gov: CVE-2023-43138
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2023-43138
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-012826 // NVD: CVE-2023-43138

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

problemtype:Command injection (CWE-77) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-012826 // NVD: CVE-2023-43138

EXTERNAL IDS

db:NVDid:CVE-2023-43138

Trust: 2.6

db:JVNDBid:JVNDB-2023-012826

Trust: 0.8

sources: JVNDB: JVNDB-2023-012826 // NVD: CVE-2023-43138

REFERENCES

url:https://github.com/7r4c4r/cve/blob/main/tplink-tl-er5120g/command%20injection/02/command%20injection02.md

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-43138

Trust: 0.8

sources: JVNDB: JVNDB-2023-012826 // NVD: CVE-2023-43138

SOURCES

db:JVNDBid:JVNDB-2023-012826
db:NVDid:CVE-2023-43138

LAST UPDATE DATE

2024-08-14T14:43:00.654000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2023-012826date:2023-12-19T06:42:00
db:NVDid:CVE-2023-43138date:2023-09-22T02:12:01.367

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2023-012826date:2023-12-19T00:00:00
db:NVDid:CVE-2023-43138date:2023-09-20T20:15:12.303