Command Injection Vulnerability in TPLINK TL-ER5120G Product
CVE-2023-43138
8.8HIGH
What is CVE-2023-43138?
The TPLINK TL-ER5120G device is vulnerable to command injection when an attacker modifies NAPT rules post-authentication. If the rule name contains an injection point, the vulnerability allows unauthorized command execution, potentially compromising the device's integrity and the network it serves.