Command Injection Vulnerability in TOTOLINK CA300-PoE Product
CVE-2023-24140
9.8CRITICAL
What is CVE-2023-24140?
The TOTOLINK CA300-PoE version V6.2c.884 has a command injection vulnerability that arises in the setNetworkDiag function due to improper handling of the NetDiagPingNum parameter, which allows attackers to execute arbitrary commands. This vulnerability can lead to unauthorized access and manipulation of network diagnostics, compromising device integrity and security.