VYPR
Critical severity9.8NVD Advisory· Published Aug 21, 2023· Updated Jun 17, 2026

CVE-2023-39617

CVE-2023-39617

Description

TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.

Affected products

4
  • cpe:2.3:o:totolink:x5000r_firmware:9.1.0cu.2089_b20211224:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:totolink:x5000r_firmware:9.1.0cu.2089_b20211224:*:*:*:*:*:*:*
    • cpe:2.3:o:totolink:x5000r_firmware:9.1.0cu.2350_b20230313:*:*:*:*:*:*:*
  • Totolink/X5000Rcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: V9.1.0cu.2089_B20211224, V9.1.0cu.2350_B20230313

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.