Command Execution Vulnerability in TOTOLINK X6000R Router
CVE-2023-48807
9.8CRITICAL
What is CVE-2023-48807?
The TOTOLINK X6000R router version V9.4.0cu.852_B20230719 contains a command execution vulnerability within the shttpd file. Specifically, the sub_4119A0 function improperly handles input parameters from the front-end, allowing an attacker to exploit the Uci_Set_The_Str function when it interacts with the CsteSystem function. This flaw creates opportunities for unauthorized command execution, potentially compromising the router's security and enabling attackers to manipulate the system.