Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfcp-527j-53hf

Опубликовано: 05 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input RebootSystem leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input RebootSystem leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 32%
0.00122
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 5.3
nvd
9 месяцев назад

A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input RebootSystem leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
fstec
9 месяцев назад

Уязвимость функции RebootSystem файла /cgi-bin/cstecgi.cgi микропрограммного обеспечения роутеров TOTOLINK A720R, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 32%
0.00122
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-287
CWE-306