'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-06-29 | |
| Rule Name: | TOTOLINK A3700R Command Injection Vulnerability (CVE-2023-46574) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function. | |
| Impact: | Allows remote attackers to execute arbitrary commands on the router, leading to complete system compromise and potential use as part of botnet infrastructure. | |
| Affected OS: | Network Device | |
| Reference: | https://github.com/OraclePi/repo/blob/main/totolink%20A3700R/1/A3700R%20%20V9.1.2u.6165_20211012%20vuln.md |
|
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |