Command Execution Vulnerability in TOTOLINK X6000R Firmware
CVE-2023-48800
9.8CRITICAL
What is CVE-2023-48800?
A command execution vulnerability exists in the TOTOLINK X6000R firmware due to improper handling of user input in the shttpd file. The sub_417338 function retrieves parameters from the front-end and uses the snprintf function to format them before passing them to the CsteSystem function, which can lead to unauthorized command execution by attackers. This poses a significant risk as malicious actors could exploit this flaw to gain control of affected devices, potentially compromising network security.