CVE-2023-48812: OS Command Injection
In TOTOLINK X6000R V9.4.0cu.852B20230719, the shttpd file sub4119A0 function obtains fields from the front-end through Uci Set The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-48812?
CVE-2023-48812 is a command execution vulnerability in TOTOLINK X6000R V9.4.0cu.852_B20230719.
How does the vulnerability in TOTOLINK X6000R V9.4.0cu.852_B20230719 occur?
The vulnerability occurs when the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_Set_The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
What is the severity of CVE-2023-48812?
The severity of CVE-2023-48812 is rated as critical with a CVSS score of 9.8.
What software version is affected by CVE-2023-48812?
TOTOLINK X6000R V9.4.0cu.852_B20230719 is affected by CVE-2023-48812.
How can I fix the vulnerability in TOTOLINK X6000R V9.4.0cu.852_B20230719?
To fix the vulnerability, it is recommended to update TOTOLINK X6000R firmware to a version that addresses the vulnerability.