Cyber Resilience

CVE-2023-4411

MediumPublic PoC

Published: 18 August 2023

Published
18 August 2023
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score 0.0107 78.2th percentile
Risk Priority 13 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2023-4411 is a medium-severity OS Command Injection (CWE-78) vulnerability in Totolink Ex1200L Firmware. Its CVSS base score is 6.3 (Medium).

Operationally, ranked in the top 21.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis

A vulnerability classified as critical has been identified in the TOTOLINK EX1200L wireless range extender running firmware EN_V9.3.5u.6146_B20201023. The issue resides in the setTracerouteCfg function, where improper handling of user-supplied input enables OS command injection, tracked under CWE-78. The flaw is remotely triggerable without user interaction and carries a CVSS 3.1 base score of 6.3.

An authenticated attacker with network access can supply crafted parameters to the affected function, resulting in arbitrary command execution on the device. Public exploit code has been released, allowing an adversary to leverage the injection to potentially alter device configuration, exfiltrate data, or pivot within the local network.

The EPSS score for this CVE rose from a low baseline to a peak of 0.0645 on 2025-01-22 before receding to its current value of 0.0107, indicating that exploitation interest increased well after the 2023 disclosure. No vendor patch or mitigation guidance has been issued, as the manufacturer did not respond to early disclosure attempts.

EU & UK References

Vulnerability details

A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public…

more

and may be used. VDB-237514 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

totolink
ex1200l firmware
9.3.5u.6146_b20201023

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-78

Platform-independent apps typically execute inside a managed runtime or sandbox that restricts direct OS command execution, reducing the ability to exploit OS command injection.

addresses: CWE-78

Validates inputs to block special elements that would alter OS command execution.

References