First published: Fri Feb 03 2023(Updated: )
A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink T8 Firmware | =v4.1.5cu | |
TOTOLINK T8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24156 is classified as a high-severity command injection vulnerability.
To mitigate CVE-2023-24156, update the TOTOLINK T8 firmware to version 4.1.5cu or later.
CVE-2023-24156 is a command injection vulnerability that allows for arbitrary command execution.
CVE-2023-24156 affects the TOTOLINK T8 device running firmware version 4.1.5cu.
An attacker can exploit CVE-2023-24156 by sending a crafted MQTT packet that targets the ip parameter in the recvSlaveUpgstatus function.