Totolink A3600R
cpe:2.3:h:totolink:a3600r:*:*:*:*:*:*:*, +1 more
- 4.1.2cu.5182_B20201102
A command injection vulnerability has been identified in the Totolink A3600R router running firmware version 4.1.2cu.5182_B20201102. The issue arises in the setNoticeCfg function within the Parameter Handler component, specifically in the file /cgi-bin/cstecgi.cgi. The vulnerability allows for remote exploitation by manipulating the NoticeUrl parameter, which is user-controllable. The exploitation of this vulnerability could lead to unauthorized command execution on the device.
Exploitation of this vulnerability allows for pre-authentication remote command execution on the affected device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.