TOTOLINK N600R
cpe:2.3:h:totolink:n600r:*:*:*:*:*:*:*, +1 more
- V4.3.0cu.7647_B20210106
- V4.3.0cu.7866_B20220506
A command injection vulnerability has been identified in the TOTOLINK N600R router, specifically in version V4.3.0cu.7647_B20210106. The issue arises in the setWiFiWpsConfig function, where the pin parameter is vulnerable to injection attacks.
Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the device.
The vulnerability can be reproduced by sending a crafted JSON payload to the setWiFiWpsConfig function. The payload must include a pin value that contains the injected command. This can be done using a tool that allows for sending HTTP requests, such as curl or Postman.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.