In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.
2023-10-31T15:15:09.830
2024-11-21T08:29:36.500
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | a3300r_firmware | 17.0.0cu.557_b20221024 | Yes |
Hardware | totolink | a3300r | - | No |