PT-2022-11728 · Totolink · Totolink Ex1200T

Published

2022-06-03

·

Updated

2023-08-08

·

CVE-2021-42884

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK EX1200T version 4.1.2cu.5215
Description The issue concerns a remote command injection vulnerability. This vulnerability is located in the setDeviceName function of the global.so file, allowing control over the deviceName to launch an attack.
Recommendations For TOTOLINK EX1200T version 4.1.2cu.5215, consider restricting access to the setDeviceName function in the global.so file as a temporary workaround until a patch is available.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-42884

Affected Products

Totolink Ex1200T