CVE-2023-46414: Command Injection
TOTOLINK X6000R v9.4.0cu.652B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub 41D494 function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46414?
CVE-2023-46414 is a remote command execution vulnerability in TOTOLINK X6000R v9.4.0cu.652_B20230116 firmware.
What is the severity of CVE-2023-46414?
The severity of CVE-2023-46414 is critical with a CVSS score of 9.8.
How does CVE-2023-46414 affect TOTOLINK X6000R?
CVE-2023-46414 allows remote attackers to execute arbitrary commands on TOTOLINK X6000R v9.4.0cu.652_B20230116 firmware.
How can I fix CVE-2023-46414?
To fix CVE-2023-46414, it is recommended to update the TOTOLINK X6000R firmware to a non-vulnerable version.
Where can I find more information about CVE-2023-46414?
More information about CVE-2023-46414 can be found at the following references: [Reference 1](https://www.totolink.cn/index.php/home/menu/detail.html?menu_listtpl=download&id=88&ids=36), [Reference 2](https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X6000R/14/1.md)