First published: Thu Feb 16 2023(Updated: )
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A7100ru Firmware | =7.4cu.2313_b20191024 | |
TOTOlink A7100RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24238 is critical with a CVSS score of 9.8.
I cannot provide assistance on exploiting vulnerabilities, my purpose is to provide information on vulnerabilities and how to protect against them.
To fix the command injection vulnerability, apply the latest firmware update provided by Totolink.
If you are using TOTOlink A7100RU(V7.4cu.2313_B20191024), you are vulnerable to the command injection vulnerability. Apply the latest firmware update to mitigate the risk.
More information about CVE-2023-24238 can be found at the following reference: https://github.com/Am1ngl/ttt/tree/main/20