TOTOLINK EX1800T
cpe:2.3:h:totolink:ex1800t:*:*:*:*:*:*:*, +1 more
- 9.1.0cu.2112_B20220316
A critical OS command injection vulnerability has been identified in the TOTOLINK EX1800T router, specifically in version 9.1.0cu.2112_B20220316. The issue arises in the '/cgi-bin/cstecgi.cgi' file, where the 'setRebootScheCfg' function improperly handles the 'mode', 'week', 'minute', and 'recHour' arguments. This vulnerability can be exploited remotely, allowing attackers to inject and execute arbitrary OS commands on the device.
Successful exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.
To reproduce this vulnerability, send a request to the '/cgi-bin/cstecgi.cgi' endpoint with the 'setRebootScheCfg' function. Include the 'mode', 'week', 'minute', and 'recHour' arguments, carefully crafted to inject OS commands. The injection can be verified by observing the execution of the injected commands on the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.