CVE-2023-43135: TP-Link Tl-ER5120G Firmware

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

Affected products

  • TP-Link Tl-ER5120G Firmware: version 2.0.0 only

Published 2023-09-20. Last modified 2026-06-17.