CVE-2021-42888: OS Command Injection
Published Jun 3, 2022
·Updated
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.
Affected Software
2 affected components
TOTOLINK EX1200T firmware=4.1.2cu.5215
TOTOLINK EX1200T
Event History
Jun 3, 2022
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
Description
Frequently Asked Questions
1
What is CVE-2021-42888?
CVE-2021-42888 is a remote command injection vulnerability found in TOTOLINK EX1200T V4.1.2cu.5215 firmware.
2
How severe is CVE-2021-42888?
CVE-2021-42888 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2021-42888 work?
CVE-2021-42888 allows an attacker to control the langType parameter to execute malicious commands remotely.
4
Is version 4.1.2cu.5215 of TOTOLINK EX1200T firmware affected by CVE-2021-42888?
Yes, version 4.1.2cu.5215 of TOTOLINK EX1200T firmware is affected by CVE-2021-42888.
5
How can I fix CVE-2021-42888?
To fix CVE-2021-42888, it is recommended to update the firmware of TOTOLINK EX1200T to a version that addresses the vulnerability.