S4E just found a low dns any record query
critical·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-30013 Scanner

CVE-2023-30013 scanner - Unauthenticated Command Injection vulnerability in TOTOLink X5000R Firmware

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-30013
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The TOTOLink X5000R is a high-performance router designed for home and small office use. It offers advanced features such as dual-band Wi-Fi for improved wireless coverage, multiple connectivity options, and enhanced security mechanisms to protect network communications. The firmware versions V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 are specifically designed to provide users with stable and secure internet access, while also enabling various network management functions. This router is widely used due to its reliability, ease of setup, and comprehensive functionality aimed at enhancing user experience and network security.

CVE-2023-30013 identifies a critical unauthenticated command injection vulnerability present in specific firmware versions of the TOTOLink X5000R router. This vulnerability allows remote attackers to execute arbitrary commands on the router without needing authentication, through the command parameter in the setTracerouteCfg setting. This flaw exposes the router to potential unauthorized access, data manipulation, or complete system compromise, posing a significant security risk to the network infrastructure and connected devices.

The vulnerability is triggered by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint, which improperly handles input validation for the command parameter within the setTracerouteCfg function. By appending shell commands after a legitimate traceroute command, attackers can inject and execute malicious commands on the device's operating system. This issue highlights the critical need for stringent input validation and sanitization in firmware development to prevent command execution vulnerabilities.

Exploiting this vulnerability could lead to complete router compromise, unauthorized access to the network, interception and manipulation of network traffic, installation of malware, and potential lateral movement within the network infrastructure. For users and organizations, this could result in sensitive data breaches, loss of network availability, and exposure to further cyber-attacks, severely impacting privacy, security, and operational continuity.

By utilizing the comprehensive security scanning services offered by S4E, users can proactively detect and mitigate vulnerabilities like CVE-2023-30013 in their digital infrastructure. Our platform's detailed vulnerability assessments, real-time monitoring, and expert remediation guidance empower users to strengthen their cybersecurity defenses, maintain compliance, and protect against evolving cyber threats. Join S4E today to ensure your network and digital assets remain secure and resilient against unauthorized access and cyber-attacks.

 

References

Solution Advice
  1. Immediately update the firmware of TOTOLink X5000R routers to the latest version provided by the manufacturer that addresses this vulnerability.
  2. Restrict network access to router management interfaces to trusted IP addresses only.
  3. Regularly monitor and audit network traffic for unusual or unauthorized activities.
  4. Implement strong, unique passwords for router administration and enable multi-factor authentication if available.
  5. Conduct periodic security assessments of network devices to identify and address potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-30013 scanner - Unauthenticated Command Injection vulnerability in TOTOLink X5000R Firmware S4E