CVE-2023-33487: Command Injection
TOTOLINK X5000R V9.1.0u.6118B20201102 and V9.1.0u.6369B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33487?
CVE-2023-33487 is a command insertion vulnerability in TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 firmware versions.
How does CVE-2023-33487 affect TOTOLINK X5000R?
CVE-2023-33487 allows an attacker to execute arbitrary commands through the "ip" parameter in the setDiagnosisCfg function of TOTOLINK X5000R firmware.
What is the severity of CVE-2023-33487?
CVE-2023-33487 has a severity rating of 9.8 (critical).
How can I fix CVE-2023-33487?
To fix CVE-2023-33487, it is recommended to update TOTOLINK X5000R firmware to versions that have addressed the vulnerability.
Where can I find more information about CVE-2023-33487?
You can find more information about CVE-2023-33487 at the following link: https://github.com/Kazamayc/vuln/tree/main/TOTOLINK/X5000R/4