CVE-2023-43318

TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.
References
Link Resource
https://github.com/str2ver/CVE-2023-43318/tree/main Third Party Advisory
https://seclists.org/fulldisclosure/2024/Mar/9 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-sg2210p_firmware:5.0:build_20211201:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-sg2210p:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-03-06 00:15

Updated : 2024-03-12 15:01


NVD link : CVE-2023-43318

Mitre link : CVE-2023-43318

CVE.ORG link : CVE-2023-43318


JSON object : View

Products Affected

tp-link

  • tl-sg2210p
  • tl-sg2210p_firmware