CVE-2023-24140 | TOTOLINK CA300-PoE 6.2c.884 setNetworkDiag NetDiagPingNum command injection (EUVD-2023-28203)
A vulnerability described as critical has been identified in TOTOLINK CA300-PoE 6.2c.884. The impacted element is the function setNetworkDiag. Such manipulation of the argument NetDiagPingNum leads to command injection.
This vulnerability is documented as CVE-2023-24140. The attack requires being on the local network. There is not any exploit available.