Command Injection Vulnerability in TOTOLINK LR350 Router
CVE-2023-37148
9.8CRITICAL
What is CVE-2023-37148?
The TOTOLINK LR350 router has a command injection vulnerability in the setUssd function, specifically through the ussd parameter. This flaw allows remote attackers to execute arbitrary commands on the affected device, potentially leading to unauthorized access or manipulation of the router's settings. It's crucial for users to address this vulnerability to safeguard their network and prevent potential exploitation.