PT-2023-25817 · Totolink · Totolink A3300R

CVE-2023-37172

·

Published

2023-07-07

·

Updated

2023-07-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3300R version 17.0.0cu.557 B20221024
Description A command injection issue was found in the setDiagnosisCfg function via the ip parameter.
Recommendations For version 17.0.0cu.557 B20221024, avoid using the ip parameter in the setDiagnosisCfg function until a fix is available. Consider restricting access to the setDiagnosisCfg function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-37172

Affected Products

Totolink A3300R