CVE-2023-48801
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 1, 2023
Updated: Dec 6, 2023
CWE ID 77
Summary
CVE-2023-48801 is a vulnerability affecting TOTOLINK X6000R firmware version V9.4.0cu.852_B20230719. In the shttpd file's sub_415534 function, user input is obtained and combined using the snprintf function before being passed to the CsteSystem function. This configuration results in a command execution vulnerability, allowing an attacker to execute arbitrary commands on the targeted system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Totolink X6000R Firmware
Affected Vendors
- TOTOLINK