PT-2022-11729 · Totolink · Totolink Ex1200T

Published

2022-06-03

·

Updated

2023-08-08

·

CVE-2021-42885

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK EX1200T version 4.1.2cu.5215
Description The issue concerns a remote command injection vulnerability. It is located in the setDeviceMac function of the global.so file, allowing control over the deviceName to launch an attack.
Recommendations For TOTOLINK EX1200T version 4.1.2cu.5215, consider disabling the setDeviceMac function in the global.so file as a temporary workaround until a patch is available. Restrict access to the global.so file to minimize the risk of exploitation. Avoid using the deviceName variable in the affected function until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-42885

Affected Products

Totolink Ex1200T