TOTOLINK A6000R
cpe:2.3:h:totolink:a6000r:*:*:*:*:*:*:*, +1 more
- V1.0.1-B20201211.2000
A command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in firmware version V1.0.1-B20201211.2000. The vulnerability arises in the reset_wifi function, where the devname parameter can be manipulated to inject and execute arbitrary commands on the device.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
The vulnerability can be reproduced by sending a GET request to the /cgi-bin/luci/admin/mtk/wifi/reset/ endpoint. The devname parameter should be injected with a command, such as 'ls>111.txt', which will be executed on the device. This injection can be verified by checking the result of the executed command.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.