CVE-2023-38563 is a critical vulnerability affecting TP-Link Archer C1200 and C9 routers, specifically firmware versions prior to 'Archer C1200(JP)_V2_230508' and 'Archer C9(JP)_V3_230508' respectively. This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary operating system commands with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 8.8. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability's nature (CWE-78: Improper Neutralization of Special Elements used in an OS Command) presents a significant risk if exploited. Organizations should prioritize patching affected devices to mitigate this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 230508CPE matchmatch criteria | cpe:2.3:o:tp-link:archer_c1200_firmware:*:*:*:*:*:*:*:* | ||
< 230508CPE matchmatch criteria | cpe:2.3:o:tp-link:archer_c9_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.