TOTOLINK A800R
cpe:2.3:h:totolink:a800r:*:*:*:*:*:*:*, +1 more
- V4.1.2cu.5137_B20200730
A pre-authentication remote command execution vulnerability has been identified in several TOTOLINK router models, including the A800R, A810R, A830R, A950RG, A3000RU, and A3100R. The vulnerability arises in the NTPSyncWithHost function, where the hostTime parameter is improperly handled, allowing for unauthorized command execution on the device.
Exploitation of this vulnerability allows for remote command execution on the affected devices.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.