Command Injection Vulnerability in TOTOLINK CA300-PoE Router
CVE-2023-24144
9.8CRITICAL
What is CVE-2023-24144?
The TOTOLINK CA300-PoE router in version V6.2c.884 is vulnerable to command injection due to improper validation of the 'hour' parameter in the setRebootScheCfg function. This flaw allows an attacker to execute arbitrary commands that can alter device configurations and potentially compromise the security of the device and the network it serves.