CVE-2023-39617: Command Injection
TOTOLINK X5000RV9.1.0cu.2089B20211224 and X5000RV9.1.0cu.2350B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39617?
CVE-2023-39617 is a remote code execution (RCE) vulnerability in TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 firmware versions.
How severe is CVE-2023-39617?
CVE-2023-39617 is considered critical with a severity score of 9.8.
Which software versions are affected by CVE-2023-39617?
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 firmware versions are affected by CVE-2023-39617.
How can the CVE-2023-39617 vulnerability be exploited?
The CVE-2023-39617 vulnerability can be exploited via the lang parameter in the setLanguageCfg function.
Is there a fix available for CVE-2023-39617?
Currently, there is no available fix for CVE-2023-39617. It is recommended to follow the vendor's advisory for updates and patches.