CVE-2023-46574
CRITICAL EXPLOITED NUCLEITOTOLINK A3700R <9.1.2u.6165_20211012 - RCE
Title source: llmDescription
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
Nuclei Templates (1)
TOTOLINK A3700R - Command Injection
CRITICALVERIFIEDby DhiyaneshDk
Shodan:
title:"Totolink" || http.title:"totolink"
FOFA:
title="totolink"
Scores
CVSS v3
9.8
EPSS
0.9344
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-08-09
CWE
CWE-77
Status
published
Products (1)
totolink/a3700r_firmware
9.1.2u.6165_20211012
Published
Oct 25, 2023
Tracked Since
Feb 18, 2026