Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chwf-9c6x-wv85

Опубликовано: 05 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.

The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.

EPSS

Процентиль: 95%
0.19992
Средний

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.

EPSS

Процентиль: 95%
0.19992
Средний

Дефекты

CWE-77