Command Execution Vulnerability in TOTOLINK X6000R Router
CVE-2023-48811
9.8CRITICAL
What is CVE-2023-48811?
A vulnerability in the TOTOLINK X6000R router allows an attacker to execute arbitrary commands through the malformed handling of input fields in the shttpd file. The flaw arises from the sub_4119A0 function improperly utilizing the Uci_Set_Str function which is subsequently passed to the CsteSystem function, enabling unauthorized command execution on the device. This could lead to unauthorized access and potential exposure of sensitive information.