CVE-2023-24154: Command Injection
Published Feb 3, 2023
·Updated
TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.
Affected Software
4 affected components
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
All of the following
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24154?
CVE-2023-24154 has a medium severity rating due to its potential for command injection.
2
Which versions of TOTOLINK T8 are affected by CVE-2023-24154?
CVE-2023-24154 specifically affects the TOTOLINK T8 firmware version v4.1.5cu.
3
How do I fix CVE-2023-24154?
To mitigate CVE-2023-24154, update the TOTOLINK T8 to the latest firmware version that addresses this vulnerability.
4
What impact does CVE-2023-24154 have?
CVE-2023-24154 could allow attackers to execute arbitrary commands on the affected device, compromising its security.
5
Is there a known exploit for CVE-2023-24154?
As of now, there are no publicly available exploits specifically documented for CVE-2023-24154.