PT-2023-30280 · Totolink · Totolink X6000R

Published

2023-10-31

·

Updated

2024-09-06

·

CVE-2023-46979

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK X6000R version 9.4.0cu.852 B20230719
Description A command injection issue was found via the enable parameter in the setLedCfg function. This allows for potential command injection attacks.
Recommendations For TOTOLINK X6000R version 9.4.0cu.852 B20230719, consider disabling the setLedCfg function until a patch is available to prevent command injection attacks. Restrict access to the enable parameter in the affected function to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-46979

Affected Products

Totolink X6000R