CVE-2023-31856: Totolink CP300+ Firmware

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.

Affected products

  • Totolink CP300+ Firmware: version 5.2cu.7594_b20200910 only

Published 2023-05-16. Last modified 2026-06-17.