CVE-2023-52028

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

Basic Information

CVE State
PUBLISHED
Reserved Date
December 26, 2023
Published Date
January 11, 2024
Last Updated
June 20, 2025
Vendor
TOTOlink
Product
A3700R
Description
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.
Tags
edge

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

Score
15.49% (Percentile: 94.35%) as of 2025-07-29

SSVC Information

Exploitation
poc
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2025-07-07 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-07-08 12:01:51 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel