CVE-2023-24156: Command Injection
Published Feb 3, 2023
·Updated
A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Affected Software
4 affected components
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
All of the following
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24156?
CVE-2023-24156 is classified as a high-severity command injection vulnerability.
2
How do I fix CVE-2023-24156?
To mitigate CVE-2023-24156, update the TOTOLINK T8 firmware to version 4.1.5cu or later.
3
What type of vulnerability is CVE-2023-24156?
CVE-2023-24156 is a command injection vulnerability that allows for arbitrary command execution.
4
Which devices are affected by CVE-2023-24156?
CVE-2023-24156 affects the TOTOLINK T8 device running firmware version 4.1.5cu.
5
How does an attacker exploit CVE-2023-24156?
An attacker can exploit CVE-2023-24156 by sending a crafted MQTT packet that targets the ip parameter in the recvSlaveUpgstatus function.