An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
id: CVE-2023-46574
info:
name: TOTOLINK A3700R - Command Injection
author: DhiyaneshDk
severi
...