PT-2022-18180 · Totolink · Totolink A7000R+1

Published

2022-03-15

·

Updated

2024-09-12

·

CVE-2022-27004

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink routers X5000R version 9.1.0u.6118 B20201102 Totolink routers A7000R version 9.1.0u.6115 B20201022
Description The issue is related to a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This allows attackers to execute arbitrary commands via a crafted request.
Recommendations For Totolink routers X5000R version 9.1.0u.6118 B20201102, consider disabling the Tunnel 6in4 function until a patch is available. For Totolink routers A7000R version 9.1.0u.6115 B20201022, restrict access to the remote6in4 parameter in the Tunnel 6in4 function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-27004

Affected Products

Totolink A7000R
Totolink X5000R