CVE-2021-42890: OS Command Injection
Published Jun 3, 2022
·Updated
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
Affected Software
2 affected components
TOTOLINK EX1200T firmware=4.1.2cu.5215
TOTOLINK EX1200T
Event History
Jun 3, 2022
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
Frequently Asked Questions
1
What is CVE-2021-42890?
CVE-2021-42890 is a remote command injection vulnerability found in TOTOLINK EX1200T V4.1.2cu.5215 firmware.
2
How severe is CVE-2021-42890?
CVE-2021-42890 has a severity score of 9.8 (Critical).
3
What is the affected software version of CVE-2021-42890?
CVE-2021-42890 affects TOTOLINK EX1200T V4.1.2cu.5215 firmware.
4
How can CVE-2021-42890 be exploited?
CVE-2021-42890 allows remote attackers to execute arbitrary commands by exploiting the NTPSyncWithHost function in the file system.so of TOTOLINK EX1200T V4.1.2cu.5215.
5
Is TOTOLINK EX1200T V4.1.2cu.5215 vulnerable to CVE-2021-42890?
Yes, TOTOLINK EX1200T V4.1.2cu.5215 firmware is vulnerable to CVE-2021-42890.