Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-46574 PoC — TOTOLINK A3700R 命令注入漏洞

Source
Associated Vulnerability
Title:TOTOLINK A3700R 命令注入漏洞 (CVE-2023-46574)
Description:TOTOLINK A3700R是中国吉翁电子(TOTOLINK)公司的一款无线路由器。 TOTOLINK A3700R v.9.1.2u.6165_20211012版本存在安全漏洞,该漏洞源于允许远程攻击者通过UploadFirmwareFile函数的FileName参数执行任意代码。
Description
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
File Snapshot

id: CVE-2023-46574 info: name: TOTOLINK A3700R - Command Injection author: DhiyaneshDk severi ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.