Remote Code Execution Vulnerability in TOTOLINK A3300R Router
CVE-2023-37170
9.8CRITICAL
Summary
The TOTOLINK A3300R router has been identified with a vulnerability allowing unauthenticated remote code execution through the lang parameter in the setLanguageCfg function. This flaw could potentially enable an attacker to execute arbitrary commands on the device, compromising the integrity of the network and exposing sensitive information. It is critical for users to apply the latest firmware updates and mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved