Totolink · Totolink A720R · CVE-2021-27708
Name of the Vulnerable Software and Affected Versions:
TOTOLINK X5000R version v9.1.0u.6118 B20201102
TOTOLINK A720R version v4.1.5cu.470 B20200911
Description:
The issue allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because a function executes glibc's system function with untrusted input. The `command` parameter is directly passed to the attacker, allowing them to control the `command` field and attack the OS.
Recommendations:
For TOTOLINK X5000R version v9.1.0u.6118 B20201102, consider disabling the function that executes the system command with untrusted input until a patch is available.
For TOTOLINK A720R version v4.1.5cu.470 B20200911, restrict access to the `command` parameter in the affected HTTP request to minimize the risk of exploitation.