CVE-2023-37146: Command Injection
Published Jul 7, 2023
·Updated
TOTOLINK LR350 V9.3.5u.6369B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
Affected Software
4 affected components
TOTOLINK Lr350 Firmware=9.3.5u.6369_b20220309
TOTOLINK LR350
All of the following
TOTOLINK Lr350 Firmware=9.3.5u.6369_b20220309
TOTOLINK LR350
Event History
Jul 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for TOTOLINK LR350 command injection vulnerability?
The vulnerability ID for TOTOLINK LR350 command injection vulnerability is CVE-2023-37146.
2
What software version is affected by the TOTOLINK LR350 command injection vulnerability?
The TOTOLINK LR350 command injection vulnerability affects software version 9.3.5u.6369_b20220309.
3
How severe is the TOTOLINK LR350 command injection vulnerability?
The severity of the TOTOLINK LR350 command injection vulnerability is rated as critical with a severity value of 9.8.
4
What is the Common Weakness Enumeration (CWE) ID for the TOTOLINK LR350 command injection vulnerability?
The Common Weakness Enumeration (CWE) ID for the TOTOLINK LR350 command injection vulnerability is CWE-77.
5
Is there a fix available for the TOTOLINK LR350 command injection vulnerability?
A fix or security patch for the TOTOLINK LR350 command injection vulnerability may be available from the vendor. It is recommended to check with TOTOLINK for the latest updates.