← Back to browse · API

CVE-2023-31856

Severity
CRITICAL
CVSS
9.8
EPSS
0.02909
Risk score
40.22
CISA KEV
No
PoC
No
Published
2023-05-16
Modified
2025-01-23
First seen
2026-08-07
Aliases
EUVD-2023-36146, GHSA-PCCP-9P7Q-3G5M
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-36146

Description

A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.

References