Command Execution Vulnerability in TOTOLINK X6000R Router
CVE-2023-48807

9.8CRITICAL

Key Information:

Vendor
Totolink
Vendor
CVE Published:
30 November 2023

Summary

The TOTOLINK X6000R router version V9.4.0cu.852_B20230719 contains a command execution vulnerability within the shttpd file. Specifically, the sub_4119A0 function improperly handles input parameters from the front-end, allowing an attacker to exploit the Uci_Set_The_Str function when it interacts with the CsteSystem function. This flaw creates opportunities for unauthorized command execution, potentially compromising the router's security and enabling attackers to manipulate the system.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.