CVE-2023-24184: Command Injection
Published Feb 21, 2023
·Updated
TOTOLink A7100RU V7.4cu.2313B20191024 was discovered to contain a command injection vulnerability.
Affected Software
4 affected components
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
All of the following
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
Event History
Feb 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-24184?
CVE-2023-24184 refers to a command injection vulnerability found in TOTOLink A7100RU V7.4cu.2313_B20191024 firmware.
2
How severe is CVE-2023-24184?
CVE-2023-24184 is classified as a critical vulnerability with a severity score of 9.8 out of 10.
3
Which software version is affected by CVE-2023-24184?
TOTOLink A7100RU V7.4cu.2313_B20191024 firmware is affected by CVE-2023-24184.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-24184?
CVE-2023-24184 is associated with CWE-77, which is the Cross-Site Scripting (XSS) vulnerability.
5
Is TOTOLink A7100RU V7.4cu.2313_B20191024 firmware vulnerable?
Yes, the TOTOLink A7100RU V7.4cu.2313_B20191024 firmware is vulnerable to CVE-2023-24184.