CVE-2023-51028: OS Command Injection
Published Dec 22, 2023
·Updated
TOTOLINK EX1800T 9.1.0cu.2112B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtenderConfig interface of the cstecgi.cgi.
Affected Software
2 affected components
All of the following
TOTOLINK Ex1800t Firmware=9.1.0cu.2112_b20220316
TOTOLINK EX1800T
Event History
Dec 22, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-51028?
CVE-2023-51028 has a high severity due to its potential for unauthorized arbitrary command execution.
2
How do I fix CVE-2023-51028?
Fix CVE-2023-51028 by upgrading the TOTOLINK EX1800T firmware to the latest version available.
3
What devices are affected by CVE-2023-51028?
CVE-2023-51028 affects the TOTOLINK EX1800T running firmware version 9.1.0cu.2112_B20220316.
4
What is the nature of the vulnerability in CVE-2023-51028?
The vulnerability in CVE-2023-51028 allows unauthorized command execution via the apcliChannel parameter in the setWiFiExtenderConfig interface.
5
Is the TOTOLINK EX1800T hardware itself vulnerable in CVE-2023-51028?
No, the hardware of the TOTOLINK EX1800T is not inherently vulnerable; the issue lies within the specific firmware version.