Vulnerability Details CVE-2023-48859
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-48859
-
cpe:2.3:h:totolink:a3002ru:-
-
cpe:2.3:o:totolink:a3002ru_firmware:2.0.0-b20190902.1958