First published: Tue Feb 14 2023(Updated: )
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Ca300-poe Firmware | =6.2c.884 | |
TOTOLINK CA300-PoE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24161 is classified as a command injection vulnerability, which can potentially allow attackers to execute arbitrary commands.
To fix CVE-2023-24161, you should update the TOTOLINK CA300-PoE firmware to version 6.2c.884 or later.
CVE-2023-24161 affects TOTOLINK CA300-PoE running firmware version 6.2c.884.
The webWlanIdx parameter in the setWebWlanIdx function is exploited in CVE-2023-24161 to perform command injection.
Yes, CVE-2023-24161 can be exploited remotely if an attacker has access to the vulnerable web interface.