CVE-2021-43664: Command Injection
Published Mar 30, 2022
·Updated
totolink EX300v2 V4.0.3c.140B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.
Affected Software
2 affected components
TOTOLINK Ex300 V2 Firmware=4.0.3c.140_b20210429
TOTOLINK Ex300 V2
Event History
Mar 30, 2022
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of totolink EX300_v2?
The vulnerability ID of totolink EX300_v2 is CVE-2021-43664.
2
What is the severity level of CVE-2021-43664?
The severity level of CVE-2021-43664 is critical.
3
What is the affected software version of CVE-2021-43664?
The affected software version of CVE-2021-43664 is totolink EX300_v2 V4.0.3c.140_B20210429.
4
What is the CWE classification of CVE-2021-43664?
The CWE classification of CVE-2021-43664 is CWE-77.
5
How can I fix the command injection vulnerability in totolink EX300_v2?
To fix the command injection vulnerability in totolink EX300_v2, it is recommended to update to a patched version of the firmware provided by the manufacturer.