CVE-2023-29802: Command Injection
Published Apr 14, 2023
·Updated
TOTOLINK X18 V9.1.0cu.2024B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
Affected Software
6 affected components
TOTOLINK X18 Firmware=9.1.0cu.2021_b20220326
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
All of the following
Any of the following
TOTOLINK X18 Firmware=9.1.0cu.2021_b20220326
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
Event History
Apr 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-29802?
CVE-2023-29802 is a command injection vulnerability in TOTOLINK X18 V9.1.0cu.2024_B20220329 firmware.
2
How severe is CVE-2023-29802?
CVE-2023-29802 has a severity rating of 9.8 (critical).
3
Which software versions are affected by CVE-2023-29802?
The affected software versions are Totolink X18 Firmware 9.1.0cu.2021_b20220326 and 9.1.0cu.2024_b20220329.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-29802?
The CWE ID for CVE-2023-29802 is CWE-77 (Improper Neutralization of Special Elements used in a Command).
5
How can I fix CVE-2023-29802?
To fix CVE-2023-29802, update your Totolink X18 firmware to a version that is not vulnerable.