Command Execution Vulnerability in TOTOLINK X6000R Router
CVE-2023-48807
9.8CRITICAL
Summary
The TOTOLINK X6000R router version V9.4.0cu.852_B20230719 contains a command execution vulnerability within the shttpd file. Specifically, the sub_4119A0 function improperly handles input parameters from the front-end, allowing an attacker to exploit the Uci_Set_The_Str function when it interacts with the CsteSystem function. This flaw creates opportunities for unauthorized command execution, potentially compromising the router's security and enabling attackers to manipulate the system.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved