ID

VAR-202305-0511


CVE

CVE-2023-30013


TITLE

TOTOLINK X5000R Operating system command injection vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202305-313

DESCRIPTION

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter

Trust: 0.99

sources: NVD: CVE-2023-30013 // VULMON: CVE-2023-30013

AFFECTED PRODUCTS

vendor:totolinkmodel:x5000rscope:eqversion:9.1.0u.6369_b20230113

Trust: 1.0

vendor:totolinkmodel:x5000rscope:eqversion:9.1.0u.6118_b20201102

Trust: 1.0

sources: NVD: CVE-2023-30013

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-30013
value: CRITICAL

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2023-30013
value: CRITICAL

Trust: 1.0

CNNVD: CNNVD-202305-313
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2023-30013
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 2.0

sources: CNNVD: CNNVD-202305-313 // NVD: CVE-2023-30013 // NVD: CVE-2023-30013

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.0

sources: NVD: CVE-2023-30013

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202305-313

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-202305-313

EXTERNAL IDS

db:NVDid:CVE-2023-30013

Trust: 1.7

db:PACKETSTORMid:174799

Trust: 1.0

db:CNNVDid:CNNVD-202305-313

Trust: 0.6

db:VULMONid:CVE-2023-30013

Trust: 0.1

sources: VULMON: CVE-2023-30013 // CNNVD: CNNVD-202305-313 // NVD: CVE-2023-30013

REFERENCES

url:https://github.com/kazamayc/vuln/tree/main/totolink/x5000r/2

Trust: 1.7

url:http://packetstormsecurity.com/files/174799/totolink-wireless-routers-remote-command-execution.html

Trust: 1.0

url:https://cxsecurity.com/cveshow/cve-2023-30013/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2023-30013 // CNNVD: CNNVD-202305-313 // NVD: CVE-2023-30013

SOURCES

db:VULMONid:CVE-2023-30013
db:CNNVDid:CNNVD-202305-313
db:NVDid:CVE-2023-30013

LAST UPDATE DATE

2025-01-30T22:49:20.012000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-30013date:2023-05-05T00:00:00
db:CNNVDid:CNNVD-202305-313date:2023-05-12T00:00:00
db:NVDid:CVE-2023-30013date:2025-01-29T18:15:45.250

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-30013date:2023-05-05T00:00:00
db:CNNVDid:CNNVD-202305-313date:2023-05-05T00:00:00
db:NVDid:CVE-2023-30013date:2023-05-05T14:15:09.147