PT-2022-6527 · Totolink · Totolink A7000R+1

Published

2022-03-15

·

Updated

2024-09-12

·

CVE-2022-27003

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Totolink routers X5000R version 9.1.0u.6118 B20201102 Totolink routers A7000R version 9.1.0u.6115 B20201022
Description The issue is related to a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This allows attackers to execute arbitrary commands via a crafted request, potentially enabling remote execution of arbitrary code.
Recommendations For Totolink routers X5000R version 9.1.0u.6118 B20201102, consider disabling the Tunnel 6rd function until a patch is available. For Totolink routers A7000R version 9.1.0u.6115 B20201022, restrict access to the relay6rd parameter in the Tunnel 6rd function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-02026
CVE-2022-27003

Affected Products

Totolink A7000R
Totolink X5000R