TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
2023-05-31T13:15:09.697
2025-01-09T19:15:16.783
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | totolink | x5000r_firmware | 9.1.0u.6118_b20201102 | Yes |
| Hardware | totolink | x5000r | - | No |
| Operating System | totolink | x5000r_firmware | 9.1.0u.6369_b20230113 | Yes |
| Hardware | totolink | x5000r | - | No |