Showing 4 vulnerabilities on this page for Archer AX5400

Signals CISA KEV Ransomware Nuclei
TP-Link vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.

CWE-78Jul 4, 2024
CVSS6.8v3.1EPSS0.362%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

TP-Link archer_ax3000_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.

CWE-78Jan 10, 2024
CVSS8.8v3.1EPSS1.07%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.

CWE-78Jan 10, 2024
CVSS8.0v3.1EPSS0.446%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.

CWE-78Jan 10, 2024
CVSS8.8v3.1EPSS0.531%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX