← Voltar para CVEs
CVE-2021-27710
CRITICAL9.8
Descricao
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "ip" parameter is directly passed to the attacker, allowing them to control the "ip" field to attack the OS.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado4/14/2021
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
totolink:a720rtotolink:a720r_firmwaretotolink:x5000rtotolink:x5000r_firmware
Fraquezas (CWE)
CWE-78
Referencias
https://hackmd.io/Hy3oVgtcQiuqAtv9FdylHw(cve@mitre.org)
https://hackmd.io/KjXzQdjDRjOuRjoZZXQo_A(cve@mitre.org)
https://hackmd.io/Hy3oVgtcQiuqAtv9FdylHw(af854a3a-2127-422b-91ae-364da2661108)
https://hackmd.io/KjXzQdjDRjOuRjoZZXQo_A(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.