First published: Fri Feb 03 2023(Updated: )
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Ca300-poe Firmware | =6.2c.884 | |
TOTOLINK CA300-PoE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24145 is classified as a critical command injection vulnerability.
To mitigate CVE-2023-24145, upgrade to the latest version of TOTOLINK CA300-PoE firmware that addresses this vulnerability.
The affected version of firmware for CVE-2023-24145 is 6.2c.884.
CVE-2023-24145 specifically affects the TOTOLINK CA300-PoE device.
CVE-2023-24145 is a command injection vulnerability found in the setUnloadUserData function.