CVE-2023-6437: TP-Link EX20V AX1800, TP-Link Archer c5v AC1200, TP-Link Td-w9970, TP-Link Td-w9970v3, TP-Link VX220-g2u, TP-Link VN020-g2u
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3, TP-Link VX220-G2u, TP-Link VN020-G2u allows authenticated OS Command Injection. This issue affects TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3 : through 20240328. Also the vulnerability continues in the TP-Link VX220-G2u and TP-Link VN020-G2u models due to the products not being produced and supported.
Affected products
- TP-Link TP-Link EX20V AX1800, TP-Link Archer c5v AC1200, TP-Link Td-w9970, TP-Link Td-w9970v3, TP-Link VX220-g2u, TP-Link VN020-g2u: up to and including 20240328
Published 2024-03-28. Last modified 2026-06-17.