Lucene search

K
cveMitreCVE-2023-33486
HistoryMay 31, 2023 - 1:15 p.m.

CVE-2023-33486

2023-05-3113:15:09
CWE-77
mitre
web.nvd.nist.gov
25
cve-2023-33486
totolink
command insertion
vulnerability
setopmodecfg
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.013

Percentile

86.1%

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the “hostName” parameter.

Affected configurations

Nvd
Node
totolinkx5000r_firmwareMatch9.1.0u.6118_b20201102
AND
totolinkx5000rMatch-
Node
totolinkx5000r_firmwareMatch9.1.0u.6369_b20230113
AND
totolinkx5000rMatch-
VendorProductVersionCPE
totolinkx5000r_firmware9.1.0u.6118_b20201102cpe:2.3:o:totolink:x5000r_firmware:9.1.0u.6118_b20201102:*:*:*:*:*:*:*
totolinkx5000r-cpe:2.3:h:totolink:x5000r:-:*:*:*:*:*:*:*
totolinkx5000r_firmware9.1.0u.6369_b20230113cpe:2.3:o:totolink:x5000r_firmware:9.1.0u.6369_b20230113:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.013

Percentile

86.1%

Related for CVE-2023-33486