CVE-2023-37149: Command Injection
Published Jul 7, 2023
·Updated
TOTOLINK LR350 V9.3.5u.6369B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
Affected Software
4 affected components
TOTOLINK Lr350 Firmware=9.3.5u.6369_b20220309
TOTOLINK LR350
All of the following
TOTOLINK Lr350 Firmware=9.3.5u.6369_b20220309
TOTOLINK LR350
Event History
Jul 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37149?
The severity of CVE-2023-37149 is critical with a CVSS score of 9.8.
2
What is the affected software of CVE-2023-37149?
The affected software of CVE-2023-37149 is TOTOLINK LR350 V9.3.5u.6369_B20220309 firmware.
3
What is the vulnerability type of CVE-2023-37149?
The vulnerability type of CVE-2023-37149 is command injection.
4
How can I exploit the command injection vulnerability in CVE-2023-37149?
We do not provide information on how to exploit vulnerabilities. It is recommended to follow responsible disclosure guidelines and inform the vendor or development team about the vulnerability.
5
How do I mitigate the command injection vulnerability in CVE-2023-37149?
To mitigate the command injection vulnerability in CVE-2023-37149, it is recommended to update to a patched version or apply the fix provided by the vendor.