CVE-2023-29799: Command Injection
Published Apr 14, 2023
·Updated
TOTOLINK X18 V9.1.0cu.2024B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
Affected Software
2 affected components
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
Event History
Apr 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-29799?
The severity of CVE-2023-29799 is critical.
2
What is the affected software version of CVE-2023-29799?
The affected software version of CVE-2023-29799 is Totolink X18 Firmware 9.1.0cu.2024_b20220329.
3
How can the command injection vulnerability be exploited in CVE-2023-29799?
The command injection vulnerability in CVE-2023-29799 can be exploited through the hostname parameter in the setOpModeCfg function.
4
Is TOTOLINK X18 vulnerable to CVE-2023-29799?
No, TOTOLINK X18 is not vulnerable to CVE-2023-29799.
5
How do I fix the command injection vulnerability in CVE-2023-29799?
To fix the command injection vulnerability in CVE-2023-29799, it is recommended to apply the latest firmware update provided by Totolink.