CVE-2023-46422: Command Injection
TOTOLINK X6000R v9.4.0cu.652B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub411994 function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46422?
CVE-2023-46422 is a remote command execution (RCE) vulnerability in TOTOLINK X6000R v9.4.0cu.652_B20230116 firmware.
How severe is CVE-2023-46422?
CVE-2023-46422 has a severity rating of 9.8, which is considered critical.
Which software version is affected by CVE-2023-46422?
TOTOLINK X6000R v9.4.0cu.652_B20230116 firmware is affected by CVE-2023-46422.
How can I fix the CVE-2023-46422 vulnerability?
To fix the CVE-2023-46422 vulnerability, update the TOTOLINK X6000R firmware to a version that is not affected.
Where can I find more information about CVE-2023-46422?
You can find more information about CVE-2023-46422 at the following references: [Reference 1](https://www.totolink.cn/index.php/home/menu/detail.html?menu_listtpl=download&id=88&ids=36), [Reference 2](https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X6000R/9/1.md).