In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
2024-08-12T20:15:09.203
2024-08-13T17:09:44.943
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | totolink | x5000r_firmware | 9.1.0u.6369_b20230113 | Yes |
Hardware | totolink | x5000r | - | No |