PT-2024-14371 · Totolink · Totolink X6000R

Kee02P

·

Published

2024-01-16

·

Updated

2024-08-30

·

CVE-2023-52042

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK X6000R version 9.4.0cu.852 B20230719
Description An issue discovered in the sub 4117F8 function allows attackers to run arbitrary commands via the lang parameter.
Recommendations For TOTOLINK X6000R version 9.4.0cu.852 B20230719, consider disabling the sub 4117F8 function until a patch is available. Restrict access to the lang parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-52042

Affected Products

Totolink X6000R