CVE-2023-52039: Command Injection
Published Jan 24, 2024
·Updated
An issue discovered in TOTOLINK X6000R v9.4.0cu.852B20230719 allows attackers to run arbitrary commands via the sub415AA4 function.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Jan 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-52039?
CVE-2023-52039 is a critical vulnerability that allows attackers to execute arbitrary commands on the affected device.
2
How do I fix CVE-2023-52039?
To mitigate CVE-2023-52039, update the TOTOLINK X6000R firmware to the latest version released after v9.4.0cu.852_B20230719.
3
What types of attacks can CVE-2023-52039 facilitate?
CVE-2023-52039 can facilitate remote code execution attacks by allowing unauthorized command execution.
4
Which devices are affected by CVE-2023-52039?
CVE-2023-52039 specifically affects the TOTOLINK X6000R firmware version 9.4.0cu.852_B20230719.
5
Is there a workaround for CVE-2023-52039?
Currently, there are no recommended workarounds for CVE-2023-52039 other than applying the firmware update.