PT-2022-11735 · Totolink · Totolink Ex1200T

Published

2022-06-03

·

Updated

2023-08-08

·

CVE-2021-42890

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK EX1200T version 4.1.2cu.5215
Description The issue concerns a remote command injection vulnerability. This vulnerability is located in the NTPSyncWithHost function of the system.so file, allowing control over hostTime to launch an attack.
Recommendations For TOTOLINK EX1200T version 4.1.2cu.5215, consider disabling the NTPSyncWithHost function as a temporary workaround until a patch is available. Restrict access to the system.so file to minimize the risk of exploitation. Avoid using the hostTime variable in the affected function until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-42890

Affected Products

Totolink Ex1200T