Loading HuntDB...

GHSA-22wf-fg96-jprv

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

Related CVEs

Key Information

GHSA ID
GHSA-22wf-fg96-jprv
Published
December 4, 2023 3:31 PM
Last Modified
December 7, 2023 9:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.