CVE-2023-50147: OS Command Injection
There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822B20200513.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50147?
CVE-2023-50147 is categorized as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2023-50147?
To remediate CVE-2023-50147, users should update the firmware of the TOTOlink A3700R router to a version that is not V9.1.2u.5822_B20200513.
What products are affected by CVE-2023-50147?
CVE-2023-50147 affects the TOTOlink A3700R router specifically using firmware version V9.1.2u.5822_B20200513.
What impact does CVE-2023-50147 have on users?
If exploited, CVE-2023-50147 can allow an attacker to execute arbitrary commands on the affected TOTOlink A3700R router.
Is there a workaround for CVE-2023-50147?
Currently, the best course of action for CVE-2023-50147 is to update to a secured firmware version, as no specific workaround is known.