CVE-2023-37170: OS Command Injection
TOTOLINK A3300R V17.0.0cu.557B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37170?
CVE-2023-37170 refers to a critical vulnerability found in TOTOLINK A3300R V17.0.0cu.557_B20221024 firmware, allowing unauthenticated remote code execution (RCE) through the lang parameter in the setLanguageCfg function.
How severe is CVE-2023-37170?
CVE-2023-37170 has a severity rating of 9.8, which indicates a critical vulnerability.
How can I fix CVE-2023-37170?
To fix CVE-2023-37170, it is recommended to update the TOTOLINK A3300R firmware to a version that contains the necessary security patches.
Is TOTOLINK A3300R version 17.0.0cu.557_B20221024 affected by CVE-2023-37170?
Yes, TOTOLINK A3300R version 17.0.0cu.557_B20221024 is affected by CVE-2023-37170.
Where can I find more information about CVE-2023-37170?
You can find more information about CVE-2023-37170 at the following link: [https://github.com/kafroc/Vuls/tree/main/TOTOLINK/A3300R/cmdi_1]