CVE-2023-24151: Command Injection
Published Feb 3, 2023
·Updated
A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Affected Software
4 affected components
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
All of the following
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24151?
The severity of CVE-2023-24151 is critical with a score of 9.8.
2
What is CVE-2023-24151?
CVE-2023-24151 is a command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu.
3
How can attackers exploit CVE-2023-24151?
Attackers can exploit CVE-2023-24151 by executing arbitrary commands via a crafted MQTT packet.
4
Which software versions are affected by CVE-2023-24151?
Totolink T8 Firmware version 4.1.5cu is affected by CVE-2023-24151.
5
Is TOTOLINK T8 vulnerable to CVE-2023-24151?
No, TOTOLINK T8 is not vulnerable to CVE-2023-24151.
6
How do I fix CVE-2023-24151?
Apply the security patch or update the Totolink T8 Firmware to a version that is not affected by CVE-2023-24151.