CVE-2015-9551: Critical severity totolink a850r-v1 firmware vulnerability
Published Nov 24, 2020
·Updated
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sysCmd parameter.
Affected Software
16 affected components
TOTOLINK A850r-v1 Firmware<1.0.1-b20150707.1612
TOTOLINK A850R-V1
TOTOLINK F1-v2 Firmware<2.1.1-b20150708.1646
TOTOLINK F1-V2
TOTOLINK F2-v1 Firmware<2.1.0-b20150320.1611
TOTOLINK F2-v1
TOTOLINK N150rt-v2 Firmware<2.1.1-b20150708.1548
TOTOLINK N150rt-v2
TOTOLINK N151rt-v2 Firmware<1.1-b20150708.1559
TOTOLINK N151rt-v2
TOTOLINK N300rh-v2 Firmware<2.0.1-b20150708.1625
TOTOLINK N300rh-v2
TOTOLINK N300rh-v3 Firmware<3.0.0-b20150331.0858
TOTOLINK N300rh-v3
TOTOLINK N300rt-v2 Firmware<2.1.1-b20150708.1613
TOTOLINK N300rt-v2
Event History
Nov 24, 2020
CVE Published
via MITRE·09:01 PM
Data Sourced
via MITRE·09:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9551?
CVE-2015-9551 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2015-9551?
To mitigate CVE-2015-9551, update the affected TOTOLINK devices to a firmware version later than 1.0.1-B20150707.1612 for A850R-V1 or 1.1-B20150708.1646 for F1-V2.
3
What devices are affected by CVE-2015-9551?
The affected devices include TOTOLINK A850R-V1 and F1-V2 models with specific firmware versions.
4
What impact does CVE-2015-9551 have?
CVE-2015-9551 allows an attacker to execute arbitrary code remotely through the management interface.
5
When was CVE-2015-9551 discovered?
CVE-2015-9551 was discovered in July 2015.