CVE-2023-46574

CRITICAL EXPLOITED NUCLEI

TOTOLINK A3700R <9.1.2u.6165_20211012 - RCE

Title source: llm

Description

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

Nuclei Templates (1)

TOTOLINK A3700R - Command Injection
CRITICALVERIFIEDby DhiyaneshDk
Shodan: title:"Totolink" || http.title:"totolink"
FOFA: title="totolink"

Scores

CVSS v3 9.8
EPSS 0.9344
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-08-09
CWE
CWE-77
Status published
Products (1)
totolink/a3700r_firmware 9.1.2u.6165_20211012
Published Oct 25, 2023
Tracked Since Feb 18, 2026