TOTOLINK CP900
cpe:2.3:h:totolink:cp900:*:*:*:*:*:*:*, +1 more
- CP900_V6.3c.1144_B20190715
A command injection vulnerability has been identified in the TOTOLINK CP900 outdoor CPE, specifically in version V6.3c.1144_B20190715. The issue arises in the setApRebootScheCfg function, where the hour and minute parameters can be manipulated to execute arbitrary commands. This vulnerability is exploited by sending a crafted request that includes malicious payloads in the hour or minute parameters.
Exploitation of this vulnerability allows for arbitrary command execution on the device.
To reproduce this vulnerability, send a POST request to the device's CGI interface (typically /cgi-bin/cstecgi.cgi) with the 'hour' and 'minute' parameters containing the injected commands. The device must be accessible on the local network.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.