CVE-2023-50147: Totolink a3700r Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.

Affected products

  • Totolink a3700r Firmware: version 9.1.2u.5822_b20200513 only

Published 2023-12-22. Last modified 2026-06-17.