First published: Mon Aug 21 2023(Updated: )
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink X5000r Firmware | =9.1.0cu.2089_b20211224 | |
Totolink X5000r Firmware | =9.1.0cu.2350_b20230313 | |
TOTOLINK X5000R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39617 is a remote code execution (RCE) vulnerability in TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 firmware versions.
CVE-2023-39617 is considered critical with a severity score of 9.8.
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 firmware versions are affected by CVE-2023-39617.
The CVE-2023-39617 vulnerability can be exploited via the lang parameter in the setLanguageCfg function.
Currently, there is no available fix for CVE-2023-39617. It is recommended to follow the vendor's advisory for updates and patches.