CVE-2023-48860: Totolink n300rt Firmware

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code.

Affected products

  • Totolink n300rt Firmware: version 3.2.4-b20180730.0906 only

Published 2023-12-07. Last modified 2026-06-17.