CVE-2023-24153: Command Injection
Published Feb 3, 2023
·Updated
A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Affected Software
4 affected components
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
All of the following
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24153?
CVE-2023-24153 has been classified as a critical severity vulnerability due to its potential to allow arbitrary command execution.
2
How do I fix CVE-2023-24153?
To mitigate CVE-2023-24153, update the affected TOTOLINK T8 firmware to a version that addresses this vulnerability.
3
What systems are affected by CVE-2023-24153?
CVE-2023-24153 specifically affects the TOTOLINK T8 firmware version 4.1.5cu.
4
Can CVE-2023-24153 be exploited remotely?
Yes, CVE-2023-24153 can be exploited remotely through specially crafted MQTT packets.
5
What kind of attack is associated with CVE-2023-24153?
CVE-2023-24153 is associated with command injection attacks, allowing unauthorized command execution on the device.