Critical severity9.8NVD Advisory· Published May 16, 2023· Updated Jun 17, 2026
CVE-2023-31856
CVE-2023-31856
Description
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
Affected products
3- TOTOLINK/CP300+description
- cpe:2.3:o:totolink:cp300\+_firmware:5.2cu.7594_b20200910:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/xiangbulala/CVE/blob/main/totlink.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.