CVE-2023-43453: Command Injection
Published Dec 1, 2023
·Updated
An issue in TOTOLINK X6000R V9.4.0cu.652B20230116 and V9.4.0cu.852B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.
Affected Software
3 affected components
All of the following
Any of the following
TOTOLINK X6000R Firmware=9.4.0cu.652_b20230116
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Dec 1, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-43453?
The severity of CVE-2023-43453 is critical with a score of 9.8.
2
Which versions of TOTOLINK X6000R firmware are affected by CVE-2023-43453?
TOTOLINK X6000R firmware versions 9.4.0cu.652_B20230116 and 9.4.0cu.852_B20230719 are affected by CVE-2023-43453.
3
How does CVE-2023-43453 allow remote attackers to execute arbitrary code?
CVE-2023-43453 allows remote attackers to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.
4
Is TOTOLINK X6000R version 9.4.0cu.852_B20230719 vulnerable to CVE-2023-43453?
Yes, TOTOLINK X6000R version 9.4.0cu.852_B20230719 is vulnerable to CVE-2023-43453.
5
How can I fix CVE-2023-43453?
There is currently no known fix for CVE-2023-43453. It is recommended to update to a secure version of the firmware when available or follow any instructions provided by the vendor.