PT-2022-12029 · Totolink · Totolink A720R+2

Published

2022-02-04

·

Updated

2022-02-07

·

CVE-2021-44247

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink A3100R version 4.1.2cu.5050 B20200504 Totolink A830R version 5.9c.4729 B20191112 Totolink A720R version 4.1.5cu.470 B20200911
Description The issue is related to a command injection vulnerability in the setNoticeCfg function. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.
Recommendations For Totolink A3100R version 4.1.2cu.5050 B20200504, consider disabling the setNoticeCfg function until a patch is available. For Totolink A830R version 5.9c.4729 B20191112, restrict access to the IpFrom parameter in the affected function to minimize the risk of exploitation. For Totolink A720R version 4.1.5cu.470 B20200911, avoid using the IpFrom parameter in the setNoticeCfg function until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44247

Affected Products

Totolink A3100R
Totolink A720R
Totolink A830R