{ "id": "CVE-2023-48802", "sourceIdentifier": "cve@mitre.org", "published": "2023-11-30T18:15:07.727", "lastModified": "2023-11-30T18:18:28.713", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability." } ], "metrics": {}, "references": [ { "url": "https://www.notion.so/X6000R-sub_4119A0-6-9541a9b3387a40de856a1cad692ba8d4?pvs=4", "source": "cve@mitre.org" } ] }