CVE-2023-48807 is a critical command injection vulnerability affecting TOTOLINK X6000R V9.4.0cu.852_B20230719 firmware, specifically within the shttpd file's sub_4119A0 function. This flaw allows attackers to execute arbitrary commands due to improper handling of front-end input passed to the CsteSystem function. With a CVSS score of 9.8 (Critical), it presents a severe risk, as it can be exploited remotely over the network with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in the CISA KEV catalog, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.4.0cu.852_b20230719CPE matchmatch criteria | cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.852_b20230719:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.