CVE-2023-29800
https://notcve.org/view.php?id=CVE-2023-29800
14 Apr 2023 — TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. • https://sore-pail-31b.notion.site/Command-Injection-5-e88b72309a3c4e20b7469b3679c0c7d9 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-29801
https://notcve.org/view.php?id=CVE-2023-29801
14 Apr 2023 — TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function. • https://sore-pail-31b.notion.site/Command-Injection-2-af41252fe96244209589d4e6da9aa7b7 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-29802
https://notcve.org/view.php?id=CVE-2023-29802
14 Apr 2023 — TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function. • https://sore-pail-31b.notion.site/Command-Injection-3-8eb94b608bcd48f8aa4e983d2d1c4526 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-29803
https://notcve.org/view.php?id=CVE-2023-29803
14 Apr 2023 — TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function. • https://sore-pail-31b.notion.site/Command-Inject-1-4a37b0679f69478285d1ba640e5f0897 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-26848
https://notcve.org/view.php?id=CVE-2023-26848
07 Apr 2023 — TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules. • https://github.com/Am1ngl/ttt/tree/main/23 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-26978
https://notcve.org/view.php?id=CVE-2023-26978
07 Apr 2023 — TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg. • https://github.com/Am1ngl/ttt/tree/main/28 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-27229
https://notcve.org/view.php?id=CVE-2023-27229
28 Mar 2023 — TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg. • https://github.com/Am1ngl/ttt/tree/main/30 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-27231
https://notcve.org/view.php?id=CVE-2023-27231
28 Mar 2023 — TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg. • https://github.com/Am1ngl/ttt/tree/main/31 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-27232
https://notcve.org/view.php?id=CVE-2023-27232
28 Mar 2023 — TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg. • https://github.com/Am1ngl/ttt/tree/main/32 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2022-28495
https://notcve.org/view.php?id=CVE-2022-28495
24 Mar 2023 — TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. • https://github.com/B2eFly/CVE/blob/main/totolink/CP900/3/3.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •