Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-784g-p98m-4mfw

Опубликовано: 08 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.

EPSS

Процентиль: 96%
0.2647
Средний

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.

EPSS

Процентиль: 96%
0.2647
Средний

Дефекты

CWE-77