CVE-2023-1082: Welotec TK515L

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

An remote attacker with low privileges can perform a command injection which can lead to root access.

Affected products

  • Welotec TK515L: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK515L-W: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK515L-W Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK515L Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK525L: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK525L-W: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK525L-W Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK525L Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK525U: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK525U Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK525W: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK525W Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK535L1: before v2.3.0.r5542 (fixed in v2.3.0.r5542)
  • Welotec TK535L1 Set: before v2.3.0.r5542 (fixed in v2.3.0.r5542); before 2.3.0.r5542 (fixed in 2.3.0.r5542)

Published 2024-04-09. Last modified 2026-06-17.