TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.Referenceshttps://github.com/Darry-lang1/vuln/blob/main/TOTOLINK/A3700R/5/readme.md