TOTOLINK EX1800T
cpe:2.3:h:totolink:ex1800t:*:*:*:*:*:*:*, +1 more
- 9.1.0cu.2112_B20220316
A critical OS command injection vulnerability has been identified in the TOTOLINK EX1800T wireless extender, specifically in version 9.1.0cu.2112_B20220316. The issue arises in the setWiFiExtenderConfig function within the cgi-bin/cstecgi.cgi file. The vulnerability allows remote attackers to inject and execute arbitrary operating system commands by manipulating the apcliKey/key argument.
Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.
To reproduce this vulnerability, send a request to the TOTOLINK EX1800T device's web interface, targeting the setWiFiExtenderConfig function. Include a crafted apcliKey/key argument that contains the desired OS command payload. The injection will be executed on the device's operating system, resulting in command execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.