TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
2023-05-05T14:15:09.147
2025-01-29T18:15:45.250
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | x5000r_firmware | 9.1.0u.6118_b20201102 | Yes |
Operating System | totolink | x5000r_firmware | 9.1.0u.6369_b20230113 | Yes |
Hardware | totolink | x5000r | - | No |