CVE-2023-29803: Command Injection
Published Apr 14, 2023
·Updated
TOTOLINK X18 V9.1.0cu.2024B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.
Affected Software
4 affected components
All of the following
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
TOTOLINK X18 Firmware=9.1.0cu.2024_b20220329
TOTOLINK X18
Event History
Apr 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-29803?
CVE-2023-29803 is a command injection vulnerability in TOTOLINK X18 V9.1.0cu.2024_B20220329.
2
How severe is CVE-2023-29803?
CVE-2023-29803 has a severity rating of 9.8 (critical).
3
How does CVE-2023-29803 affect Totolink X18 Firmware?
CVE-2023-29803 affects Totolink X18 Firmware version 9.1.0cu.2024_b20220329 through a command injection vulnerability.
4
Is TOTOLINK X18 vulnerable to CVE-2023-29803?
No, TOTOLINK X18 is not vulnerable to CVE-2023-29803.
5
How can I fix CVE-2023-29803?
To fix CVE-2023-29803, it is recommended to update Totolink X18 Firmware to a version that is not affected by the vulnerability.