CVE-2023-48812
Severity CVSS v4.0: 
            Pending analysis
                                                    Type: 
          
                          CWE-78
                        OS Command Injections
          
        Publication date: 
                          30/11/2023
                  Last modified: 
                          07/12/2023
                  Description
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
              Impact
Base Score 3.x
          9.80
        Severity 3.x
          CRITICAL
        Vulnerable products and versions
| CPE | From | Up to | 
|---|---|---|
| cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.852_b20230719:*:*:*:*:*:*:* | ||
| cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:* | 
To consult the complete list of CPE names with products and versions, see this page



