TOTOLINK T6
cpe:2.3:h:totolink:t6:*:*:*:*:*:*:*, +1 more
- 4.1.5cu.748
A critical command injection vulnerability has been identified in the TOTOLINK T6 router, specifically in version 4.1.5cu.748. The issue arises in the CloudSrvVersionCheck function within the /cgi-bin/cstecgi.cgi file, where the 'ip' argument can be manipulated to execute arbitrary commands. This vulnerability can be exploited remotely by sending a malicious HTTP POST request.
Exploitation of this vulnerability allows for command injection, with the potential for remote code execution.
To reproduce this vulnerability, send a crafted HTTP POST request to the TOTOLINK T6 router's /cgi-bin/cstecgi.cgi endpoint. Include a payload in the 'ip' argument that exploits the command injection flaw. The router must be running firmware version 4.1.5cu.748.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.