VYPR
Critical severity9.8NVD Advisory· Published Dec 1, 2023· Updated Jun 17, 2026

CVE-2023-48801

CVE-2023-48801

Description

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

Affected products

3
  • cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.852_b20230719:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.852_b20230719:*:*:*:*:*:*:*
    • (no CPE)
  • Totolink/X6000Rllm-fuzzy
    Range: V9.4.0cu.852_B20230719

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.