CRITICAL🇵🇱 Wersja polska

CVE-2023-52030

CVSS 9.8v3.1pub. 2024-01-11upd. 2025-05-14

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.

🤖 AI Analysis
How it works

The vulnerability is located in the setOpModeCfg function in the Totolink A3700R router software. An attacker can send a specially crafted network request to the device, which will be processed by the vulnerable function without permission verification. As a result, it is possible to execute arbitrary system commands on the device (RCE). The attack vector is network-based, does not require user interaction or any privileges.

Impact

An attacker can gain full control over the device, including reading and modifying its configuration, intercepting network traffic, and using the device as an entry point for further network actions (lateral movement). The vulnerability provides the attacker with complete access to the confidentiality, integrity, and availability of the system.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. If an update is not available, it is recommended to restrict access to the device management interface exclusively to trusted IP addresses and isolate the device from direct access from the Internet.

Who is affected

Totolink A3700R with software version v9.1.2u.5822_B20200513

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Totolink A3700r

    HW
    Totolink
    all versions
  • Totolink A3700r Firmware

    OS
    Totolink
    9.1.2u.5822_b20200513
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-42545CRITICAL9.8PL ✓same product

Buffer overflow w parametrze ssid funkcji setWizardCfg — TOTOLINK A3700R

CVE-2024-42543CRITICAL9.8PL ✓same product

Buffer overflow w TOTOLINK A3700R — parametr http_host w funkcji loginauth

CVE-2024-37637CRITICAL9.8PL ✓same product

Stack overflow w TOTOLINK A3700R — funkcja setWizardCfg (ssid5g)

CVE-2024-37632CRITICAL9.8PL ✓same product

Stack overflow w TOTOLINK A3700R — podatność w funkcji loginAuth

CVE-2024-37635CRITICAL9.8PL ✓same product

Stack overflow w TOTOLINK A3700R — funkcja setWiFiBasicCfg (ssid)