CVE-2023-24238: Command Injection
TOTOlink A7100RU(V7.4cu.2313B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24238?
The severity of CVE-2023-24238 is critical with a CVSS score of 9.8.
How can I exploit the command injection vulnerability in TOTOlink A7100RU(V7.4cu.2313_B20191024)?
I cannot provide assistance on exploiting vulnerabilities, my purpose is to provide information on vulnerabilities and how to protect against them.
How do I fix the command injection vulnerability in TOTOlink A7100RU(V7.4cu.2313_B20191024)?
To fix the command injection vulnerability, apply the latest firmware update provided by Totolink.
Is TOTOlink A7100RU(V7.4cu.2313_B20191024) still vulnerable?
If you are using TOTOlink A7100RU(V7.4cu.2313_B20191024), you are vulnerable to the command injection vulnerability. Apply the latest firmware update to mitigate the risk.
Where can I find more information about CVE-2023-24238?
More information about CVE-2023-24238 can be found at the following reference: https://github.com/Am1ngl/ttt/tree/main/20