A command injection vulnerability in the version...
Critical severity
Unreviewed
Published
Feb 3, 2023
to the GitHub Advisory Database
•
Updated Feb 18, 2023
Description
Published by the National Vulnerability Database
Feb 3, 2023
Published to the GitHub Advisory Database
Feb 3, 2023
Last updated
Feb 18, 2023
A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
References