CVE-2023-46421: Command Injection
Published Oct 25, 2023
·Updated
TOTOLINK X6000R v9.4.0cu.652B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub411D00 function.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.652_b20230116
TOTOLINK X6000R
Event History
Oct 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46421?
The severity of CVE-2023-46421 is critical with a value of 9.8.
2
What is the affected software of CVE-2023-46421?
The affected software of CVE-2023-46421 is Totolink X6000r Firmware version 9.4.0cu.652_b20230116.
3
How can the remote command execution vulnerability in TOTOLINK X6000R v9.4.0cu.652_B20230116 be exploited?
The remote command execution vulnerability in TOTOLINK X6000R v9.4.0cu.652_B20230116 can be exploited through the sub_411D00 function.
4
Is TOTOLINK X6000R v9.4.0cu.652_B20230116 vulnerable to the remote command execution vulnerability?
Yes, TOTOLINK X6000R v9.4.0cu.652_B20230116 is vulnerable to the remote command execution vulnerability.
5
Are there any available fixes for CVE-2023-46421?
Please refer to the official Totolink website for available fixes for CVE-2023-46421: https://www.totolink.cn/index.php/home/menu/detail.html?menu_listtpl=download&id=88&ids=36