CVE-2023-50651: OS Command Injection
Published Dec 30, 2023
·Updated
TOTOLINK X6000R v9.4.0cu.852B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Dec 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50651?
CVE-2023-50651 is classified as a high severity vulnerability due to its ability to allow remote command execution.
2
How do I fix CVE-2023-50651?
To fix CVE-2023-50651, update the Totolink X6000R firmware to the latest version provided by the manufacturer.
3
What is affected by CVE-2023-50651?
CVE-2023-50651 affects Totolink X6000R devices running firmware version 9.4.0cu.852_B20230719.
4
Can CVE-2023-50651 be exploited remotely?
Yes, CVE-2023-50651 can be exploited remotely through the vulnerable component /cgi-bin/cstecgi.cgi.
5
Is there a patch available for CVE-2023-50651?
Yes, the vendor has released a patch to address CVE-2023-50651, which can be obtained from their official website.