TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.
2023-10-31T14:15:11.697
2024-11-21T08:29:34.497
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | a3300r_firmware | 17.0.0cu.557_b20221024 | Yes |
Hardware | totolink | a3300r | - | No |