VYPR
High severity8.8NVD Advisory· Published Dec 6, 2023· Updated Jun 17, 2026

CVE-2023-48859

CVE-2023-48859

Description

TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.

Affected products

3
  • Totolink/A3002RUllm-fuzzy2 versions
    2.0.0-B20190902.1958+ 1 more
    • (no CPE)range: 2.0.0-B20190902.1958
    • (no CPE)
  • cpe:2.3:o:totolink:a3002ru_firmware:2.0.0-b20190902.1958:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.