CVE-2023-30307
About
An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which could lead to a denial of service.
Rainforest analyst review
This covers a set of TP-LINK routers, the TL-R473GP-AC, XDR6020, TL-R479GP-AC, TL-R4239G, TL-WAR1200L, and TL-R476G, where a session-fixation-class weakness lets attackers hijack TCP sessions, which can lead to a denial of service. The impact is availability-only and rated moderate; the outcome is disruption of sessions rather than data theft or code execution. Notably, our batch record for this entry has empty vendor and product metadata even though the description names the affected models.
TCP session hijacking leading to DoS is a disruption issue, not a takeover, and it is bounded accordingly, an attacker can interrupt connectivity but doesn't gain control of the device or its data through this alone. Routers are heavily scanned, but availability-only bugs draw less weaponization than credential or code-execution flaws, so the realistic risk is targeted disruption rather than broad botnet conscription.
Two things shape our handling. First, the empty vendor/product fields mean our automated matching won't catch this, so it needs the model list read out of the description and reconciled against our network-gear inventory manually. Second, given the availability-only impact, we rank it moderate and focus on whether any of these specific TP-LINK models sit in exposed positions where session disruption would actually hurt.
References
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2023-30307?
An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which could lead to a denial of service.
How severe is CVE-2023-30307?
CVE-2023-30307 carries a CVSS 3.1 base score of 5.3, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 60 out of 100, in the elevated band.
How is CVE-2023-30307 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality None, integrity None and availability Low.
How do I fix CVE-2023-30307?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
