CVE-2023-48859: High severity totolink a3002ru vulnerability
Published Dec 6, 2023
·Updated
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.
Affected Software
2 affected components
All of the following
TOTOLINK A3002ru Firmware=2.0.0-b20190902.1958
TOTOLINK A3002RU
Event History
Dec 6, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-48859?
CVE-2023-48859 has a high severity due to its potential for remote code execution.
2
How do I fix CVE-2023-48859?
To fix CVE-2023-48859, update the TOTOLINK A3002RU firmware to a version that mitigates this vulnerability.
3
What type of vulnerability is CVE-2023-48859?
CVE-2023-48859 is a remote code execution vulnerability resulting from improper access control.
4
Who is affected by CVE-2023-48859?
CVE-2023-48859 affects users of TOTOLINK A3002RU running firmware version 2.0.0-B20190902.1958.
5
Can CVE-2023-48859 be exploited remotely?
Yes, CVE-2023-48859 can be exploited remotely after authentication due to inadequate security measures.