Command Execution Vulnerability in TOTOLINK X6000R Router
CVE-2023-48805
9.8CRITICAL
What is CVE-2023-48805?
A command execution vulnerability exists in the TOTOLINK X6000R due to improper handling of input within the shttpd file's sub_4119A0 function. When this function processes fields from the front-end using Uci_Set_The_Str, it becomes susceptible to exploitation via the CsteSystem function, allowing unauthorized command execution.