CVE-2023-46419: Command Injection
TOTOLINK X6000R v9.4.0cu.652B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub415730 function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46419?
CVE-2023-46419 is a remote command execution (RCE) vulnerability found in TOTOLINK X6000R v9.4.0cu.652_B20230116.
How severe is CVE-2023-46419?
CVE-2023-46419 has a severity rating of 9.8 (critical).
Can CVE-2023-46419 lead to unauthorized remote access to the TOTOLINK X6000R device?
Yes, CVE-2023-46419 can allow unauthorized remote access to the TOTOLINK X6000R device.
How can I fix CVE-2023-46419?
To fix CVE-2023-46419, it is recommended to update the TOTOLINK X6000R firmware to version 9.4.0cu.652_B20230116 or newer.
Where can I find more information about CVE-2023-46419?
More information about CVE-2023-46419 can be found at the following references: [Link 1](https://www.totolink.cn/index.php/home/menu/detail.html?menu_listtpl=download&id=88&ids=36) and [Link 2](https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X6000R/6/1.md).