VYPR
Critical severity9.8NVD Advisory· Published May 16, 2023· Updated Jun 17, 2026

CVE-2023-31856

CVE-2023-31856

Description

A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.

Affected products

3
  • Totolink/CP300cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: V5.2cu.7594_B20200910
  • cpe:2.3:o:totolink:cp300\+_firmware:5.2cu.7594_b20200910:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.