CVE-2023-24236: Command Injection
TOTOlink A7100RU(V7.4cu.2313B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24236?
CVE-2023-24236 is a command injection vulnerability found in TOTOlink A7100RU(V7.4cu.2313_B20191024) routers.
How severe is CVE-2023-24236?
CVE-2023-24236 is classified as critical with a severity value of 9.8.
How does CVE-2023-24236 affect TOTOlink A7100RU(V7.4cu.2313_B20191024) routers?
CVE-2023-24236 allows an attacker to execute arbitrary commands on the affected routers via the 'province' parameter in the 'setting/delStaticDhcpRules' feature.
Is TOTOlink A7100RU(V7.4cu.2313_B20191024) the only affected software?
No, TOTOlink A7100RU(V7.4cu.2313_B20191024) is the only affected software, but TOTOlink A7100RU is not vulnerable to this issue.
How can I fix CVE-2023-24236?
To fix CVE-2023-24236, update your TOTOlink A7100RU(V7.4cu.2313_B20191024) router to a version that addresses the command injection vulnerability.