← Back

CVE-2023-28368

nvd nist
Published: Apr 11, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD

Description

TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH host keys. A fake device may be prepared to spoof the affected device with the vulnerable host key.If the administrator may be tricked to login to the fake device, the credential information for the affected device may be obtained.

Affected (2)

1 product
T2600g 28sq Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Tp Link
Version 20190530
Version 20200304
Running on/withPlatform Versions
Tp Link
T2600g 28sq
Version 1.0

References (4)

Source: vultures@jpcert.or.jp
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.