In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd...
Critical severity
Unreviewed
Published
Nov 30, 2023
to the GitHub Advisory Database
•
Updated Dec 7, 2023
Description
Published by the National Vulnerability Database
Nov 30, 2023
Published to the GitHub Advisory Database
Nov 30, 2023
Last updated
Dec 7, 2023
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
References