PT-2023-4734 · Totolink · Totolink N200Re V5
Dmknght
·
Published
2023-09-03
·
Updated
2024-05-17
·
CVE-2023-4746
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TOTOLINK N200RE V5 version 9.3.5u.6437 B20230519
Description
The issue is related to the
Validity check() function in the TOTOLINK N200RE V5 router's firmware. It involves the use of uncontrolled format strings when processing the % symbol, which can lead to format string vulnerabilities. This can be exploited remotely, allowing an attacker to execute arbitrary commands. The root cause is a format string issue that enables OS command injection by bypassing validation.Recommendations
For TOTOLINK N200RE V5 version 9.3.5u.6437 B20230519, as a temporary workaround, consider disabling the
Validity check() function until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the % symbol in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink N200Re V5