Command Injection Vulnerability in TOTOlink Router
CVE-2023-27232
9.8CRITICAL
What is CVE-2023-27232?
The TOTOlink A7100RU router version V7.4cu.2313_B20191024 is affected by a command injection vulnerability. This security flaw arises from improper handling of user input, specifically via the 'wanStrategy' parameter at the '/setting/setWanIeCfg' endpoint. Attackers could exploit this vulnerability to execute arbitrary commands on the device, potentially compromising network integrity and leading to unauthorized access.