CVE-2023-37146 | Totolink LR350 9.3.5u.6369_B20220309 UploadFirmwareFile FileName command injection (EUVD-2023-41066)
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this issue is the function UploadFirmwareFile. Such manipulation of the argument FileName leads to command injection.
This vulnerability is referenced as CVE-2023-37146. The attack needs to be initiated within the local network. No exploit is available.