First published: Tue May 16 2023(Updated: )
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Cp300\+ Firmware | =5.2cu.7594_b20200910 | |
Totolink Cp300\+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-31856.
The severity of CVE-2023-31856 is critical with a score of 9.8.
The affected software is Totolink Cp300+ Firmware version 5.2cu.7594_b20200910.
The vulnerability in CVE-2023-31856 allows attackers to execute arbitrary commands through a crafted HTTP packet.
No, Totolink Cp300+ is not vulnerable to this vulnerability.