CVE-2023-52040: Command Injection
Published Jan 24, 2024
·Updated
An issue discovered in TOTOLINK X6000R v9.4.0cu.852B20230719 allows attackers to run arbitrary commands via the sub41284C function.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Jan 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52040?
CVE-2023-52040 has been rated as a high severity vulnerability due to its ability to allow attackers to run arbitrary commands.
2
How does CVE-2023-52040 exploit the system?
CVE-2023-52040 exploits the system by manipulating the sub_41284C function to execute arbitrary commands.
3
What versions of firmware are affected by CVE-2023-52040?
CVE-2023-52040 affects TOTOLINK X6000R firmware version 9.4.0cu.852_B20230719.
4
How do I fix CVE-2023-52040?
To fix CVE-2023-52040, update the firmware of the TOTOLINK X6000R to the latest version provided by the manufacturer.
5
What devices are vulnerable due to CVE-2023-52040?
CVE-2023-52040 specifically affects the TOTOLINK X6000R AX3000 router.