CVE-2023-51035: OS Command Injection
Published Dec 22, 2023
·Updated
TOTOLINK EX1200L V9.3.5u.6146B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.
Affected Software
2 affected components
All of the following
TOTOLINK Ex1200l Firmware=9.3.5u.6146_b20201023
TOTOLINK EX1200L
Event History
Dec 22, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-51035?
CVE-2023-51035 is classified as a high severity vulnerability due to its ability to allow arbitrary command execution.
2
How do I fix CVE-2023-51035?
To fix CVE-2023-51035, upgrade the TOTOLINK EX1200L firmware to a version that addresses this vulnerability.
3
What specific feature of the TOTOLINK EX1200L is affected by CVE-2023-51035?
CVE-2023-51035 affects the cstecgi.cgi NTPSyncWithHost interface on the TOTOLINK EX1200L.
4
Can CVE-2023-51035 be exploited remotely?
Yes, CVE-2023-51035 can be exploited remotely without requiring authentication.
5
What are the potential impacts of exploiting CVE-2023-51035?
Exploiting CVE-2023-51035 can lead to unauthorized command execution, which may compromise the affected device.