TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/str2ver/CVE-2023-43318/tree/main | third party advisory |
https://seclists.org/fulldisclosure/2024/Mar/9 | third party advisory mailing list |