Описание
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used.
EPSS
Процентиль: 25%
0.00329
Низкий
6.5 Medium
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-73
Связанные уязвимости
CVSS3: 6.5
github
3 месяца назад
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used.
EPSS
Процентиль: 25%
0.00329
Низкий
6.5 Medium
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-73