PT-2022-11728 · Totolink · Totolink Ex1200T

CVE-2021-42884

·

Published

2022-06-03

·

Updated

2023-08-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK EX1200T version 4.1.2cu.5215
Description The issue concerns a remote command injection vulnerability. This vulnerability is located in the setDeviceName function of the global.so file, allowing control over the deviceName to launch an attack.
Recommendations For TOTOLINK EX1200T version 4.1.2cu.5215, consider restricting access to the setDeviceName function in the global.so file as a temporary workaround until a patch is available.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42884

Affected Products

Totolink Ex1200T