CVE-2023-4411
Published: 18 August 2023
Summary
CVE-2023-4411 is a medium-severity OS Command Injection (CWE-78) vulnerability in Totolink Ex1200L Firmware. Its CVSS base score is 6.3 (Medium).
Operationally, ranked in the top 21.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Deeper analysis
A vulnerability classified as critical has been identified in the TOTOLINK EX1200L wireless range extender running firmware EN_V9.3.5u.6146_B20201023. The issue resides in the setTracerouteCfg function, where improper handling of user-supplied input enables OS command injection, tracked under CWE-78. The flaw is remotely triggerable without user interaction and carries a CVSS 3.1 base score of 6.3.
An authenticated attacker with network access can supply crafted parameters to the affected function, resulting in arbitrary command execution on the device. Public exploit code has been released, allowing an adversary to leverage the injection to potentially alter device configuration, exfiltrate data, or pivot within the local network.
The EPSS score for this CVE rose from a low baseline to a peak of 0.0645 on 2025-01-22 before receding to its current value of 0.0107, indicating that exploitation interest increased well after the 2023 disclosure. No vendor patch or mitigation guidance has been issued, as the manufacturer did not respond to early disclosure attempts.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-54274
Vulnerability details
A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public…
more
and may be used. VDB-237514 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.