TP-Link Archer AX53 Command Injection Vulnerability
Vulnerability
A command injection vulnerability has been identified in the TP-Link Archer AX53 V1 router. This issue arises in the 'mscd' debug functionality, where inadequate input validation allows authenticated attackers to redirect logs to arbitrary files and append unvalidated file contents to shell commands. Exploitation of this vulnerability could enable the execution of malicious commands, potentially leading to full control of the device.
Impact
Exploitation of this vulnerability allows authenticated attackers to inject and execute arbitrary commands on the device, potentially leading to full control over it.
Remediation
Users are advised to download and update to the latest firmware version. The latest firmware can be downloaded from the TP-Link official website for the Archer AX53 V1.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
