CVE-2023-46979
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 31, 2023
Updated: Nov 8, 2023
CWE ID 77
Summary
CVE-2023-46979 is a newly discovered vulnerability affecting the TOTOLINK X6000R V9.4.0cu.852_B20230719 firmware. This issue allows an attacker to inject commands into the system by manipulating the enable parameter in the setLedCfg function. Successful exploitation could lead to arbitrary code execution and potential unauthorized access or data theft. Users are urged to update their firmware as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Totolink X6000R Firmware
Affected Vendors
- TOTOLINK