CVE-2023-52038: Command Injection
Published Jan 24, 2024
·Updated
An issue discovered in TOTOLINK X6000R v9.4.0cu.852B20230719 allows attackers to run arbitrary commands via the sub415C80 function.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Jan 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-52038?
CVE-2023-52038 is considered a high-severity vulnerability due to its ability to allow attackers to run arbitrary commands.
2
How do I fix CVE-2023-52038?
To fix CVE-2023-52038, update the TOTOLINK X6000R firmware to version 9.4.0cu.852_B20230719 or later.
3
What type of attack does CVE-2023-52038 facilitate?
CVE-2023-52038 facilitates command injection attacks that can potentially compromise the device.
4
Which devices are affected by CVE-2023-52038?
CVE-2023-52038 affects the TOTOLINK X6000R with firmware version 9.4.0cu.852_B20230719.
5
Can CVE-2023-52038 be exploited remotely?
Yes, CVE-2023-52038 can be exploited remotely by attackers with network access to the device.