Описание
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Ссылки
- Broken LinkThird Party Advisory
- Third Party AdvisoryVDB Entry
- Broken LinkThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:totolink:t6_firmware:v4.1.5cu.748_b20211015:*:*:*:*:*:*:*
cpe:2.3:h:totolink:t6:-:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.0446
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-77
Связанные уязвимости
github
почти 4 года назад
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
EPSS
Процентиль: 89%
0.0446
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-77