A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
2023-05-16T15:15:09.350
2025-01-23T16:15:29.030
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | cp300\+_firmware | 5.2cu.7594_b20200910 | Yes |
Hardware | totolink | cp300\+ | - | No |