TOTOLINK CA300-PoE
cpe:2.3:h:totolink:ca300-poe:*:*:*:*:*:*:*, +1 more
- 6.2c.884
A critical OS command injection vulnerability has been identified in the TOTOLINK CA300-PoE router, specifically in the firmware version 6.2c.884. The issue arises in the QuickSetting function of the ap.so file, where the hour and minute parameters can be manipulated to inject and execute arbitrary operating system commands. This vulnerability can be exploited remotely, without authentication.
Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.
To reproduce this vulnerability, send a crafted request to the CA300-PoE router's QuickSetting function, including manipulated hour and minute parameters. The injected command will be executed on the router's operating system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.