← Retour aux CVEs
CVE-2021-27710
CRITICAL9.8
Description
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "ip" parameter is directly passed to the attacker, allowing them to control the "ip" field to attack the OS.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie4/14/2021
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
totolink:a720rtotolink:a720r_firmwaretotolink:x5000rtotolink:x5000r_firmware
Faiblesses (CWE)
CWE-78
References
https://hackmd.io/Hy3oVgtcQiuqAtv9FdylHw(cve@mitre.org)
https://hackmd.io/KjXzQdjDRjOuRjoZZXQo_A(cve@mitre.org)
https://hackmd.io/Hy3oVgtcQiuqAtv9FdylHw(af854a3a-2127-422b-91ae-364da2661108)
https://hackmd.io/KjXzQdjDRjOuRjoZZXQo_A(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.