VYPR
High severity8.0NVD Advisory· Published Sep 6, 2023· Updated Jun 17, 2026

CVE-2023-40357

CVE-2023-40357

Description

Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504', Archer AX10 firmware versions prior to 'Archer AX10(JP)_V1.2_230508', and Archer AX11000 firmware versions prior to 'Archer AX11000(JP)_V1_230523'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Range: < Archer AX10(JP)_V1.2_230508
  • Range: < Archer AX50(JP)_V1_230529
  • TP-Link/Archer A10llm-fuzzy2 versions
    < Archer A10(JP)_V2_230504+ 1 more
    • (no CPE)range: < Archer A10(JP)_V2_230504
    • (no CPE)range: firmware versions prior to 'Archer A10(JP)_V2_230504'
  • Range: < Archer AX11000(JP)_V1_230523
  • TP-Link/Archer AX1500cpe-rescue2 versions
    firmware versions prior to 'Archer AX10(JP)_V1.2_230508'+ 1 more
    • (no CPE)range: firmware versions prior to 'Archer AX10(JP)_V1.2_230508'
    • (no CPE)range: firmware versions prior to 'Archer AX11000(JP)_V1_230523'
  • Range: firmware versions prior to 'Archer AX50(JP)_V1_230529'

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.