First published: Fri Jul 07 2023(Updated: )
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Lr350 Firmware | =9.3.5u.6369_b20220309 | |
TOTOLINK LR350 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-37149 is critical with a CVSS score of 9.8.
The affected software of CVE-2023-37149 is TOTOLINK LR350 V9.3.5u.6369_B20220309 firmware.
The vulnerability type of CVE-2023-37149 is command injection.
We do not provide information on how to exploit vulnerabilities. It is recommended to follow responsible disclosure guidelines and inform the vendor or development team about the vulnerability.
To mitigate the command injection vulnerability in CVE-2023-37149, it is recommended to update to a patched version or apply the fix provided by the vendor.