CVE-2023-51012: Critical severity totolink ex1800t vulnerability
Published Dec 22, 2023
·Updated
TOTOlink EX1800T v9.1.0cu.2112B20220316 is vulnerable to unauthorized arbitrary command execution in the lanGateway parameter’ of the setLanConfig interface of the cstecgi .cgi.
Affected Software
2 affected components
All of the following
TOTOLINK Ex1800t Firmware=9.1.0cu.2112_b20220316
TOTOLINK EX1800T
Event History
Dec 22, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-51012?
CVE-2023-51012 is classified as a high severity vulnerability due to its potential for unauthorized command execution.
2
How do I fix CVE-2023-51012?
To mitigate CVE-2023-51012, update the TOTOlink EX1800T firmware to the latest version that resolves this vulnerability.
3
What is affected by CVE-2023-51012?
CVE-2023-51012 specifically affects TOTOlink EX1800T firmware version 9.1.0cu.2112_B20220316.
4
What type of attack can exploit CVE-2023-51012?
CVE-2023-51012 can be exploited through unauthorized arbitrary command execution via the setLanConfig interface.
5
Is CVE-2023-51012 easily exploitable?
Yes, CVE-2023-51012 is easily exploitable if the vulnerable firmware is deployed without the recommended security measures.