CVE-2023-47167 - CVE House
Back to Database
Status published High CVE-2023-47167

A post authentication command injection vulnerability exists in the GRE...

Vulnerability Description

A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-47167

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Discovered by the Vulnerability Discovery and Research team of Cisco Talos.

Affected Vendor

Affected Software

ER7206 Omada Gigabit VPN Router
Vulnerable Versions:
1.3.0 build 20230322 Rel.70591

Timeline

Official Publish: February 6th, 2024
Last Modified: November 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)