Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-83cm-g6q5-c98f

Опубликовано: 08 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet.

TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet.

EPSS

Процентиль: 94%
0.13299
Средний

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet.

EPSS

Процентиль: 94%
0.13299
Средний

9.8 Critical

CVSS3

Дефекты

CWE-77