CVE-2023-31856 | TOTOLINK CP300+ 5.2cu.7594_B20200910 HTTP Packet NTPSyncWithHostof hostTime command injection (EUVD-2023-36146)
A vulnerability described as critical has been identified in TOTOLINK CP300+ 5.2cu.7594_B20200910. This impacts the function NTPSyncWithHostof of the component HTTP Packet Handler. Executing manipulation of the argument hostTime can lead to command injection.
This vulnerability is registered as CVE-2023-31856. The attack requires access to the local network. No exploit is available.