First published: Fri Jun 03 2022(Updated: )
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Ex1200t Firmware | =4.1.2cu.5215 | |
TOTOLINK EX1200T |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42890 is a remote command injection vulnerability found in TOTOLINK EX1200T V4.1.2cu.5215 firmware.
CVE-2021-42890 has a severity score of 9.8 (Critical).
CVE-2021-42890 affects TOTOLINK EX1200T V4.1.2cu.5215 firmware.
CVE-2021-42890 allows remote attackers to execute arbitrary commands by exploiting the NTPSyncWithHost function in the file system.so of TOTOLINK EX1200T V4.1.2cu.5215.
Yes, TOTOLINK EX1200T V4.1.2cu.5215 firmware is vulnerable to CVE-2021-42890.