First published: Fri May 05 2023(Updated: )
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink X5000r Firmware | =9.1.0u.6118_b20201102 | |
Totolink X5000r Firmware | =9.1.0u.6369_b20230113 | |
TOTOLINK X5000R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-30013 is critical.
TOTOLINK X5000R firmware version 9.1.0u.6118_B20201102 is affected by CVE-2023-30013.
TOTOLINK X5000R firmware version 9.1.0u.6369_B20230113 is affected by CVE-2023-30013.
The command insertion vulnerability in CVE-2023-30013 is in the setting/setTracerouteCfg function.
An attacker can exploit CVE-2023-30013 by executing arbitrary commands through the "command" parameter.