CVE-2023-43135

CRITICAL

TP-LINK ER5120G <4.0.2.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

Scores

CVSS v3 9.8
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
tp-link/tl-er5120g_firmware 2.0.0 build_210817
Published Sep 20, 2023
Tracked Since Feb 18, 2026