CVE-2023-48859: Totolink a3002ru Firmware

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.

Affected products

  • Totolink a3002ru Firmware: version 2.0.0-b20190902.1958 only

Published 2023-12-06. Last modified 2026-06-17.