CVE-2023-50147OS Command Injection in A3700r Firmware

Severity
9.8CRITICALNVD
EPSS
1.2%
top 21.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 22

Description

There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDtotolink/a3700r_firmware9.1.2u.5822_b20200513

🔴Vulnerability Details

2
GHSA
GHSA-9f6c-6m59-979h: There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi2023-12-22
CVEList
CVE-2023-50147: There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi2023-12-22
CVE-2023-50147 — OS Command Injection | cvebase