Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5g5r-9pxv-4v7g

Опубликовано: 18 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-237514 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-237514 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 78%
0.01108
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 6.3
nvd
больше 2 лет назад

A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-237514 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость функции setTracerouteCfg микропрограммного обеспечения роутеров TOTOLINK EX1200L, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 78%
0.01108
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-78