Command Injection Vulnerability in TOTOLINK Router Products
CVE-2023-37145
9.8CRITICAL
What is CVE-2023-37145?
TOTOLINK LR350 routers have been identified as having a command injection vulnerability. This flaw is exploited through the hostname parameter in the setOpModeCfg function, potentially allowing attackers to execute arbitrary commands on the system. Users should ensure they are using the latest firmware and follow best security practices to mitigate risks associated with this vulnerability.