CVE-2023-46574 Scanner

Targets the web management interface's formSetDebugCfg endpoint; attacker injects OS commands via the enable parameter to gain root shell access.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

12 days 15 hours

Scan only one

URL

Toolbox

The TOTOLINK A3700R is a dual-band wireless router powered by an 880MHz dual-core processor, supporting IEEE 802.11ac wave2 and MU-MIMO technology. It is widely used in home and small office environments to deliver high-speed internet connectivity, manage network traffic, and provide wireless coverage. Its web-based management interface allows administrators to configure settings like Wi-Fi, firewall, and system tools.

CVE-2023-46574 is an OS Command Injection vulnerability in the TOTOLINK A3700R firmware version 9.1.2u.6165_20211012. It arises because the web management interface fails to properly sanitize user-supplied input before passing it to system commands. This lack of validation allows an attacker to inject arbitrary operating system commands that are executed with root privileges.

The vulnerability specifically exists in the formSetDebugCfg function, accessible via the /cgi-bin/luci/;stok=/locale endpoint. The vulnerable parameter is 'enable', which is directly concatenated into a shell command without any filtering or escaping. An attacker can send a crafted HTTP POST request containing malicious command sequences, such as command separators like ';' or '&&', to trigger execution.

If exploited, an attacker can gain complete remote control over the router, including the ability to modify network settings, intercept traffic, launch further attacks on internal devices, or use the router as part of a botnet. Given the CVSS score of 9.8, this vulnerability poses a critical risk to network security and requires immediate remediation.

Get started to protecting your digital assets