First published: Fri Jun 03 2022(Updated: )
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control thedeviceName to attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Ex1200t Firmware | =4.1.2cu.5215 | |
TOTOLINK EX1200T |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42884 is a vulnerability in TOTOLINK EX1200T V4.1.2cu.5215 that allows remote command injection.
CVE-2021-42884 works by exploiting the setDeviceName function in the global.so file to control the device name and launch attacks.
CVE-2021-42884 has a severity rating of 9.8 (Critical).
To fix CVE-2021-42884, users should update their TOTOLINK EX1200T firmware to version 4.1.2cu.5215.
More information about CVE-2021-42884 can be found at the following link: [https://github.com/p1Kk/vuln/blob/main/totolink_ex1200t_devicename_rce.md](https://github.com/p1Kk/vuln/blob/main/totolink_ex1200t_devicename_rce.md)