First published: Mon Oct 16 2023(Updated: )
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Cp300\+ Firmware | =5.2cu.7594_b20200910 | |
Totolink Cp300\+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-36954 is critical, with a severity value of 9.8.
CVE-2023-36954 allows for command injection in TOTOLINK CP300+ firmware version 5.2cu.7594_B20200910 and before.
Yes, TOTOLINK CP300+ firmware version 5.2cu.7594_B20200910 and before is vulnerable to CVE-2023-36954.
To fix CVE-2023-36954, it is recommended to update TOTOLINK CP300+ firmware to a version that contains the security patch.
You can find more information about CVE-2023-36954 at the following reference: [link](https://github.com/Archerber/bug_submit/blob/main/TOTOLINK/CP300%2B_3.md)