2024-05-25 21:48:12 +02:00
|
|
|
### [CVE-2023-24160](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24160)
|
|
|
|

|
|
|
|

|
|
|
|

|
|
|
|
|
|
|
|
### Description
|
|
|
|
|
|
|
|
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
|
|
|
|
|
|
|
|
### POC
|
|
|
|
|
|
|
|
#### Reference
|
|
|
|
- https://github.com/iceyjchen/VulnerabilityProjectRecords/blob/main/setPasswordCfg_admuser/setPasswordCfg_admuser.md
|
|
|
|
|
|
|
|
#### Github
|
|
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
|
|
- https://github.com/iceyjchen/VulnerabilityProjectRecords
|
2024-07-25 21:25:12 +00:00
|
|
|
- https://github.com/jiceylc/VulnerabilityProjectRecords
|
2024-05-25 21:48:12 +02:00
|
|
|
|