CVE-2023-33486: Command Injection
TOTOLINK X5000R V9.1.0u.6118B20201102 and V9.1.0u.6369B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33486?
The severity of CVE-2023-33486 is critical with a CVSS score of 9.8.
How does CVE-2023-33486 affect the TOTOLINK X5000R firmware?
CVE-2023-33486 affects TOTOLINK X5000R firmware versions 9.1.0u.6118_B20201102 and 9.1.0u.6369_B20230113.
What is the vulnerability in TOTOLINK X5000R firmware related to CVE-2023-33486?
CVE-2023-33486 is a command insertion vulnerability in the setOpModeCfg function of TOTOLINK X5000R firmware.
How can an attacker exploit CVE-2023-33486?
An attacker can exploit CVE-2023-33486 by executing arbitrary commands through the "hostName" parameter.
Is there a fix available for CVE-2023-33486?
At the moment, there is no known fix available for CVE-2023-33486. It is recommended to follow the vendor's security advisories for updates.