CVE-2023-46484: Command Injection
Published Oct 31, 2023
·Updated
An issue in TOTOlink X6000R V9.4.0cu.852B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Oct 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46484?
The severity of CVE-2023-46484 is critical.
2
What is the affected software for CVE-2023-46484?
The affected software for CVE-2023-46484 is TOTOlink X6000R V9.4.0cu.852_B20230719.
3
How can a remote attacker exploit CVE-2023-46484?
A remote attacker can exploit CVE-2023-46484 by executing arbitrary code via the setLedCfg function.
4
Is TOTOlink X6000R vulnerable to CVE-2023-46484?
Yes, TOTOlink X6000R V9.4.0cu.852_B20230719 is vulnerable to CVE-2023-46484.
5
Is there a fix for CVE-2023-46484?
It is recommended to update to a secure version of TOTOlink X6000R firmware to fix CVE-2023-46484.