CVE-2023-24150: Command Injection
Published Feb 3, 2023
·Updated
A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Affected Software
4 affected components
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
All of the following
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24150?
CVE-2023-24150 is classified as a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2023-24150?
To fix CVE-2023-24150, users should upgrade to the latest version of TOTOLINK T8 firmware that addresses this vulnerability.
3
What type of attack can exploit CVE-2023-24150?
CVE-2023-24150 can be exploited through a crafted MQTT packet that allows command injection on the device.
4
Which software versions are affected by CVE-2023-24150?
CVE-2023-24150 affects TOTOLINK T8 firmware version 4.1.5cu.
5
What is the impact of CVE-2023-24150?
The impact of CVE-2023-24150 includes the potential for an attacker to execute arbitrary commands on the affected device.