Security Advisory

CVE-2023-28368

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-04-11 00:00:00
Last updated 2025-02-10 20:54:23
Assigner jpcert
State PUBLISHED

Description

TP-Link L2 switch T2600G-28SQ firmware versions prior to T2600G-28SQ(UN)_V1_1.0.6 Build 20230227 uses vulnerable SSH host keys. A fake device may be prepared to spoof the affected device with the vulnerable host key.If the administrator may be tricked to login to the fake device, the credential information for the affected device may be obtained.