Totolink A7000R cstecgi.cgi setUpgradeFW command injection
35Vexday Risk Score
Prioriza la corrección. Ella explotación observada por VulnCheck.
ssvc Attendcvss 5.3epss 2.3%
de la publicación al arma
Publicada en NVD29 ene
VulnCheck+182d
probabilidad de explotación
2.3%top 18% de las CVE
explotación observada
síVulnCheck
A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
Totolink · A7000RReferencias
https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/04_RCE_setUpgradeFW_RCE.mdhttps://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A7000R/04_RCE_setUpgradeFW_RCE.md#pochttps://vuldb.com/?ctiid.343382https://vuldb.com/?id.343382https://vuldb.com/?submit.740767https://www.totolink.net/