CVE-2023-29800: Command Injection
Published Apr 14, 2023
·Updated
TOTOLINK X18 V9.1.0cu.2024B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
Affected Software
4 affected components
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
All of the following
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
Event History
Apr 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-29800?
CVE-2023-29800 is a command injection vulnerability found in TOTOLINK X18 V9.1.0cu.2024_B20220329.
2
How severe is CVE-2023-29800?
CVE-2023-29800 is classified as critical with a severity rating of 9.8 out of 10.
3
How does CVE-2023-29800 affect TOTOLINK X18 V9.1.0cu.2024_B20220329?
CVE-2023-29800 allows attackers to execute arbitrary commands by exploiting the FileName parameter in the UploadFirmwareFile function of TOTOLINK X18 V9.1.0cu.2024_B20220329.
4
Is CVE-2023-29800 specific to TOTOLINK X18 V9.1.0cu.2024_B20220329?
Yes, CVE-2023-29800 only affects TOTOLINK X18 V9.1.0cu.2024_B20220329 firmware version.
5
How can I fix CVE-2023-29800?
To fix CVE-2023-29800, update the TOTOLINK X18 firmware to a version that addresses the command injection vulnerability.