Remote Command Execution Vulnerability in TOTOlink Router
CVE-2023-52031
9.8CRITICAL
What is CVE-2023-52031?
The TOTOlink A3700R v9.1.2u.5822_B20200513 router contains a vulnerability in the UploadFirmwareFile function, which can be exploited to perform remote command execution. This issue allows attackers to send specially crafted requests to the affected device, leading to the execution of arbitrary commands on the system. The presence of this vulnerability raises significant risks, enabling unauthorized access and potential control over network devices.
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved