In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
2024-08-12T20:15:08.820
2024-08-13T17:35:02.867
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | x5000r_firmware | 9.1.0u.6369_b20230113 | Yes |
Hardware | totolink | x5000r | - | No |