CVE-2023-24141: Command Injection
Published Feb 3, 2023
·Updated
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.
Affected Software
4 affected components
TOTOLINK Ca300-poe Firmware=6.2c.884
TOTOLINK CA300-PoE
All of the following
TOTOLINK Ca300-poe Firmware=6.2c.884
TOTOLINK CA300-PoE
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this TOTOLINK CA300-PoE vulnerability?
The vulnerability ID for this TOTOLINK CA300-PoE vulnerability is CVE-2023-24141.
2
What is the severity level of CVE-2023-24141?
CVE-2023-24141 has a severity level of critical.
3
What is the affected software version for CVE-2023-24141?
The affected software version for CVE-2023-24141 is TOTOLINK CA300-PoE V6.2c.884.
4
How does the vulnerability in TOTOLINK CA300-PoE occur?
The vulnerability in TOTOLINK CA300-PoE occurs due to a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.
5
Is TOTOLINK CA300-PoE V6.2c.884 vulnerable to CVE-2023-24141?
Yes, TOTOLINK CA300-PoE V6.2c.884 is vulnerable to CVE-2023-24141.