CVE-2023-52042: Command Injection
Published Jan 16, 2024
·Updated
An issue discovered in sub4117F8 function in TOTOLINK X6000R V9.4.0cu.852B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
Affected Software
2 affected components
All of the following
TOTOLINK X6000R Firmware=9.4.0cu.852_b20230719
TOTOLINK X6000R
Event History
Jan 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-52042?
CVE-2023-52042 is rated as a critical vulnerability due to its potential to allow attackers to execute arbitrary commands.
2
How do I fix CVE-2023-52042?
To mitigate CVE-2023-52042, upgrade the TOTOLINK X6000R firmware to version 9.4.0cu.852_B20230719 or later.
3
What impacts does CVE-2023-52042 have on the TOTOLINK X6000R?
CVE-2023-52042 can lead to unauthorized command execution, compromising the security and functionality of the device.
4
Who is affected by CVE-2023-52042?
Users of the TOTOLINK X6000R firmware version 9.4.0cu.852_B20230719 are affected by CVE-2023-52042.
5
What could an attacker achieve by exploiting CVE-2023-52042?
An attacker exploiting CVE-2023-52042 could run arbitrary commands with the same privileges as the affected TOTOLINK X6000R device.