TOTOLINK A3002R
cpe:2.3:h:totolink:a3002r:*:*:*:*:*:*:*, +1 more
- 1.1.1-B20200824.0128
A critical OS command injection vulnerability has been identified in the TOTOLINK A3002R router running firmware version 1.1.1-B20200824.0128. The issue arises in the 'formWlSiteSurvey' function of the '/boafrm/formWlSiteSurvey' file, where the 'wlanif' argument can be manipulated to execute arbitrary OS commands. This vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.
Exploitation of this vulnerability allows remote attackers to execute arbitrary operating system commands on the affected device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.