Critical severity9.8NVD Advisory· Published Oct 25, 2023· Updated Jun 17, 2026
CVE-2023-46574
CVE-2023-46574
Description
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
Affected products
3- cpe:2.3:o:totolink:a3700r_firmware:9.1.2u.6165_20211012:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/OraclePi/repo/blob/main/totolink%20A3700R/1/A3700R%20%20V9.1.2u.6165_20211012%20vuln.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.