Command Execution Vulnerability in TOTOLINK X6000R by TOTOLINK
CVE-2023-48810
9.8CRITICAL
What is CVE-2023-48810?
A command execution vulnerability has been identified in the TOTOLINK X6000R router, specifically in the handling of fields from the front-end within the shttpd file. The affected function, sub_4119A0, improperly uses user input when it calls the CsteSystem function after passing through the Uci_Set_The_Str function. This flaw could allow an attacker to execute arbitrary commands on the device, potentially compromising the integrity and security of the system and any connected networks.