TOTOLINK CA300-PoE
cpe:2.3:h:totolink:ca300-poe:*:*:*:*:*:*:*, +1 more
- 6.2c.884
A critical OS command injection vulnerability has been identified in the TOTOLINK CA300-PoE router running firmware version 6.2c.884. The issue arises in the 'setUpgradeFW' function of the 'upgrade.so' file, where the 'FileName' argument can be manipulated to execute arbitrary operating system commands. This vulnerability can be exploited remotely, and a public exploit is available.
Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.
To reproduce this vulnerability, send a crafted request to the router's 'setUpgradeFW' function, manipulating the 'FileName' argument to inject OS commands. The command injection can be verified by executing a command that returns a response, such as 'id' or 'whoami'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.