CVE-2023-46978: High severity totolink x6000r ax3000 vulnerability
Published Oct 31, 2023
·Updated
TOTOLINK X6000R V9.4.0cu.852B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Oct 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46978?
The severity of CVE-2023-46978 is high with a CVSS score of 7.5.
2
What is the vulnerability in TOTOLINK X6000R V9.4.0cu.852_B20230719?
The vulnerability in TOTOLINK X6000R V9.4.0cu.852_B20230719 is Incorrect Access Control.
3
How can attackers exploit CVE-2023-46978?
Attackers can exploit CVE-2023-46978 by resetting login password and WIFI passwords without authentication.
4
Is TOTOLINK X6000R V9.4.0cu.852_B20230719 affected by the vulnerability?
Yes, TOTOLINK X6000R V9.4.0cu.852_B20230719 is affected by the vulnerability.
5
Is there a fix for CVE-2023-46978?
At this time, there is no known fix for CVE-2023-46978. It is recommended to follow the vendor's instructions and upgrade to a secure version if available.