CVE-2023-46574
totolink a3700r_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2023-46574 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 9, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 11, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
a3700r_firmwareBrowse totolink / a3700r_firmwareDefault status: unknown | CVE List, VulnCheck | 9.1.2u.6165_20211012 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALTOTOLINK A3700R - Command InjectionCVSS 9.8
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
Impact
Unauthenticated attackers can execute arbitrary commands on the router, potentially gaining full device control and compromising network security.
Remediation
Update TOTOLINK A3700R firmware to a version newer than 9.1.2u.6165_20211012.
Source: ProjectDiscovery