VYPR
Critical severity9.8NVD Advisory· Published Dec 7, 2023· Updated Jun 17, 2026

CVE-2023-48860

CVE-2023-48860

Description

TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code.

Affected products

3
  • Totolink/CX-N300RTllm-fuzzy2 versions
    3.2.4-B20180730.0906+ 1 more
    • (no CPE)range: 3.2.4-B20180730.0906
    • (no CPE)
  • cpe:2.3:o:totolink:n300rt_firmware:3.2.4-b20180730.0906:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.