CVE-2023-33487

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published May 31, 2023
Updated: Jan 9, 2025
CWE ID 77

Summary

CVE-2023-33487 is a command injection vulnerability affecting TOTOLINK X5000R routers with firmware versions V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113. An attacker can exploit this issue by manipulating the "ip" parameter in the setDiagnosisCfg function. Successful exploitation allows the execution of arbitrary commands, potentially leading to unauthorized access, data theft, or denial-of-service attacks. Users are advised to update their firmware to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share