TOTOLINK A6000R
cpe:2.3:h:totolink:a6000r:*:*:*:*:*:*:*, +1 more
- 1.0.1-B20201211.2000
A critical command injection vulnerability has been identified in the TOTOLINK A6000R router, specifically in the firmware version 1.0.1-B20201211.2000. The issue arises in the 'apcli_cancel_wps' function within the file '/usr/lib/lua/luci/controller/mtkwifi.lua'. This vulnerability allows remote attackers to execute arbitrary commands on the device, potentially leading to a complete system compromise.
Exploitation of this vulnerability allows for unauthorized command execution on the affected router, with the potential to disrupt normal operations or manipulate the device's functions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.