CVE-2023-30054: Command Injection
Published May 5, 2023
·Updated
TOTOLINK A7100RU V7.4cu.2313B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.
Affected Software
4 affected components
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
All of the following
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
Event History
May 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
03:15 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-30054?
The severity of CVE-2023-30054 is critical with a CVSS score of 9.8.
2
How can an attacker exploit CVE-2023-30054?
An attacker can exploit CVE-2023-30054 by using a specially constructed payload to obtain a stable root shell.
3
What software is affected by CVE-2023-30054?
The affected software is TOTOLINK A7100RU V7.4cu.2313_B20191024 firmware.
4
Is TOTOlink A7100RU vulnerable to CVE-2023-30054?
No, TOTOlink A7100RU is not vulnerable to CVE-2023-30054.
5
How can I fix CVE-2023-30054?
To fix CVE-2023-30054, it is recommended to update to the latest firmware version provided by TOTOLINK.