CVE-2023-46979: Command Injection
Published Oct 31, 2023
·Updated
TOTOLINK X6000R V9.4.0cu.852B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Oct 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-46979?
CVE-2023-46979 is a command injection vulnerability in TOTOLINK X6000R V9.4.0cu.852_B20230719 firmware.
2
What is the severity of CVE-2023-46979?
CVE-2023-46979 has a severity score of 9.8 (critical).
3
How does CVE-2023-46979 affect TOTOLINK X6000R firmware?
CVE-2023-46979 affects TOTOLINK X6000R firmware version 9.4.0cu.852_B20230719.
4
How can I fix the CVE-2023-46979 vulnerability?
To fix the CVE-2023-46979 vulnerability, update the TOTOLINK X6000R firmware to a version that is not affected.
5
Where can I find more information about CVE-2023-46979?
More information about CVE-2023-46979 can be found at this link: https://github.com/shinypolaris/vuln-reports/blob/master/TOTOLINK%20X6000R/2/README.md