TOTOLINK A6000R
cpe:2.3:h:totolink:a6000r:*:*:*:*:*:*:*, +1 more
- V1.0.1-B20201211.2000
A command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in firmware version V1.0.1-B20201211.2000. The vulnerability arises in the 'enable_wsh' function within the 'system.lua' file, where the 'modifyOne' parameter can be exploited to inject arbitrary commands.
Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the device.
To reproduce this vulnerability, send a GET request to the '/cgi-bin/luci/admin/mtk/wsh_enable_submit' endpoint. Include the 'modifyOne' parameter with a payload that injects a command, such as listing directory contents and redirecting the output to a file. The injection can be verified by checking for the presence of the output file.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.