CVE-2023-31569: Command Injection
Published Jun 6, 2023
·Updated
TOTOLINK X5000R V9.1.0cu.2350B20230313 was discovered to contain a command injection via the setWanCfg function.
Affected Software
4 affected components
All of the following
TOTOLINK X5000r Firmware=9.1.0cu.2350_b20230313
TOTOLINK X5000R
TOTOLINK X5000r Firmware=9.1.0cu.2350_b20230313
TOTOLINK X5000R
Event History
Jun 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-31569?
CVE-2023-31569 refers to a command injection vulnerability found in TOTOLINK X5000R V9.1.0cu.2350_B20230313.
2
What is the severity of CVE-2023-31569?
CVE-2023-31569 has a severity rating of 9.8 (critical).
3
How does CVE-2023-31569 affect TOTOLINK X5000R V9.1.0cu.2350_B20230313?
CVE-2023-31569 allows an attacker to execute commands through the setWanCfg function in TOTOLINK X5000R V9.1.0cu.2350_B20230313.
4
Is TOTOLINK X5000R V9.1.0cu.2350_B20230313 the only affected software version?
Yes, TOTOLINK X5000R V9.1.0cu.2350_B20230313 is the only affected software version.
5
How do I fix CVE-2023-31569?
To fix CVE-2023-31569, update the firmware of TOTOLINK X5000R to a version that is not vulnerable.