PT-2022-12029 · Totolink · Totolink A720R+2
Published
2022-02-04
·
Updated
2022-02-07
·
CVE-2021-44247
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Totolink A3100R version 4.1.2cu.5050 B20200504
Totolink A830R version 5.9c.4729 B20191112
Totolink A720R version 4.1.5cu.470 B20200911
Description
The issue is related to a command injection vulnerability in the
setNoticeCfg function. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.Recommendations
For Totolink A3100R version 4.1.2cu.5050 B20200504, consider disabling the
setNoticeCfg function until a patch is available.
For Totolink A830R version 5.9c.4729 B20191112, restrict access to the IpFrom parameter in the affected function to minimize the risk of exploitation.
For Totolink A720R version 4.1.5cu.470 B20200911, avoid using the IpFrom parameter in the setNoticeCfg function until the issue is resolved.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink A3100R
Totolink A720R
Totolink A830R