TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.
References
Link Resource
https://github.com/str2ver/CVE-2023-43318/tree/main Third Party Advisory
https://seclists.org/fulldisclosure/2024/Mar/9 Mailing List Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-05T00:00:00

Updated: 2024-07-05T17:22:09.215Z

Reserved: 2023-09-18T00:00:00


Link: CVE-2023-43318

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-03-06T00:15:52.347

Modified: 2024-03-12T15:01:14.340


Link: CVE-2023-43318

JSON object: View

cve-icon Redhat Information

No data.