CVE-2023-24157: Command Injection
Published Feb 3, 2023
·Updated
A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
Affected Software
4 affected components
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
All of the following
TOTOLINK T8 Firmware=v4.1.5cu
TOTOLINK T8
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-24157?
CVE-2023-24157 is a command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu.
2
How can attackers exploit CVE-2023-24157?
Attackers can exploit CVE-2023-24157 by sending a crafted MQTT packet to execute arbitrary commands.
3
What is the severity of CVE-2023-24157?
The severity of CVE-2023-24157 is critical with a CVSS score of 9.8.
4
How can I fix CVE-2023-24157?
To fix CVE-2023-24157, update to the latest firmware version of TOTOLINK T8.
5
Is TOTOLINK T8 vulnerable to CVE-2023-24157?
No, TOTOLINK T8 is not vulnerable to CVE-2023-24157.