Record summary

CVE-2023-46574 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 9, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 11, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List, VulnCheck9.1.2u.6165_20211012affected

Nuclei templates

1
ProjectDiscoveryCRITICALTOTOLINK A3700R - Command InjectionCVSS 9.8

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

Impact

Unauthenticated attackers can execute arbitrary commands on the router, potentially gaining full device control and compromising network security.

Remediation

Update TOTOLINK A3700R firmware to a version newer than 9.1.2u.6165_20211012.

WeaknessesCWE-77
AuthorsDhiyaneshDk
Template tagscvecve2023totolinkrouteriotrcevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:totolink:a3700r_firmware:9.1.2u.6165_20211012:*:*:*:*:*:*:*
Shodan: title:"Totolink"
Shodan: http.title:"totolink"
FOFA: title="totolink"
Google: intitle:"totolink"

Source: ProjectDiscovery

References

2