CVE-2023-48192: Code Injection
Published Nov 20, 2023
·Updated
An issue in TOTOlink A3700R v.9.1.2u.6134B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.
Affected Software
2 affected components
All of the following
Totolink A3700R Firmware=9.1.2u.6134_b20201202
Totolink A3700R Firmware
Event History
Nov 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-48192.
2
What is the severity of CVE-2023-48192?
The severity of CVE-2023-48192 is high with a severity value of 7.8.
3
How does this vulnerability affect TOTOlink A3700R devices?
This vulnerability affects TOTOlink A3700R devices running firmware version 9.1.2u.6134_B20201202.
4
How can a local attacker exploit this vulnerability?
A local attacker can exploit this vulnerability by executing arbitrary code through the setTracerouteCfg function.
5
Is there a fix available for CVE-2023-48192?
Information about the fix for CVE-2023-48192 can be found on the official TOTOlink website.