Command Injection Vulnerability in TOTOLINK T8 Router
CVE-2023-24152
9.8CRITICAL
What is CVE-2023-24152?
A command injection vulnerability exists in the serverIp parameter of the function meshSlaveUpdate in the TOTOLINK T8 Router. This flaw allows attackers to execute arbitrary commands by sending specially crafted MQTT packets, potentially compromising the security and integrity of the device. Users are encouraged to apply necessary security measures to mitigate risk.