CVE-2023-48804: OS Command Injection
In TOTOLINK X6000R V9.4.0cu.852B20230719, the shttpd file, sub4119A0 function obtains fields from the front-end through Uci Set The Str function when passed to the CsteSystem function creates a command execution vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48804?
The severity of CVE-2023-48804 is critical with a CVSS score of 9.8.
How does CVE-2023-48804 affect TOTOLINK X6000R firmware version 9.4.0cu.852_b20230719?
CVE-2023-48804 affects TOTOLINK X6000R firmware version 9.4.0cu.852_b20230719 by creating a command execution vulnerability.
Is TOTOlink X6000R firmware version 9.4.0cu.852_b20230719 vulnerable?
Yes, TOTOlink X6000R firmware version 9.4.0cu.852_b20230719 is vulnerable to CVE-2023-48804.
What is the CWE ID of CVE-2023-48804?
The CWE ID of CVE-2023-48804 is 78.
Where can I find more information about CVE-2023-48804?
You can find more information about CVE-2023-48804 at the following link: [https://www.notion.so/X6000R-sub_4119A0-1-e9697e90e8b04e05a6d10c9fb7288750?pvs=4](https://www.notion.so/X6000R-sub_4119A0-1-e9697e90e8b04e05a6d10c9fb7288750?pvs=4)