CVE-2023-39618
https://notcve.org/view.php?id=CVE-2023-39618
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface. • https://sedate-class-393.notion.site/TOTOlink-3567fd9f93d84afab0d81cd8c063f9a1?pvs=4 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-39617
https://notcve.org/view.php?id=CVE-2023-39617
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. • https://sedate-class-393.notion.site/TOTOlink-ee7eb0d4cd5d43e9983296200371eff1?pvs=4 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-31569
https://notcve.org/view.php?id=CVE-2023-31569
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function. • http://totolink.com https://github.com/JeeseenSec/Report/tree/main/TOTOLINK%2CThanks https://github.com/JeeseenSec/Report/tree/main/TOTOLINK/CVE-2023-31569 https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/218.html • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-33487
https://notcve.org/view.php?id=CVE-2023-33487
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter. • https://github.com/Kazamayc/vuln/tree/main/TOTOLINK/X5000R/4 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-33486
https://notcve.org/view.php?id=CVE-2023-33486
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter. • https://github.com/Kazamayc/vuln/tree/main/TOTOLINK/X5000R/3 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •