CVE-2021-43663: Command Injection
Published Mar 30, 2022
·Updated
totolink EX300v2 V4.0.3c.140B20210429 was discovered to contain a command injection vulnerability via the component cloudupdatecheck.
Affected Software
2 affected components
TOTOLINK Ex300 V2 Firmware=4.0.3c.140_b20210429
TOTOLINK Ex300 V2
Event History
Mar 30, 2022
CVE Published
via MITRE·11:40 PM
Data Sourced
via MITRE·11:40 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-43663.
2
What is the severity rating of CVE-2021-43663?
The severity rating of CVE-2021-43663 is high with a CVSS score of 7.5.
3
What is the affected software for CVE-2021-43663?
The affected software for CVE-2021-43663 is Totolink EX300_v2 firmware version 4.0.3c.140_B20210429.
4
How was the vulnerability discovered?
The vulnerability was discovered through the component cloudupdate_check in Totolink EX300_v2 firmware version 4.0.3c.140_B20210429.
5
Is Totolink Ex300 V2 firmware version 4.0.3c.140_B20210429 vulnerable?
Yes, Totolink Ex300 V2 firmware version 4.0.3c.140_B20210429 is vulnerable to the command injection vulnerability.