Vulnerability Database

300,830

Total vulnerabilities in the database

CVE-2023-43454

An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.

  • Published: Dec 1, 2023
  • Updated: Dec 7, 2023
  • CVE: CVE-2023-43454
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWEs:

OWASP TOP 10:

Software From Fixed in
totolink / x6000r_firmware 9.4.0cu.652_b20230116 9.4.0cu.652_b20230116.x
totolink / x6000r_firmware 9.4.0cu.852_b20230719 9.4.0cu.852_b20230719.x