CVE-2021-43711: Command Injection
Published Jan 4, 2022
·Updated
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.
Affected Software
4 affected components
TOTOLINK Ex200 Firmware=4.0.3c.7646_b20201211
TOTOLINK EX200
All of the following
TOTOLINK Ex200 Firmware=4.0.3c.7646_b20201211
TOTOLINK EX200
Event History
Jan 4, 2022
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-43711?
CVE-2021-43711 is a command injection vulnerability in the downloadFlile.cgi binary file of TOTOLINK EX200 V4.0.3c.7646_B20201211.
2
How severe is CVE-2021-43711?
CVE-2021-43711 has a severity rating of 9.8 (Critical).
3
How does the command injection vulnerability in CVE-2021-43711 occur?
The vulnerability occurs when the downloadFlile.cgi binary file receives constructed GET parameters, allowing for unauthenticated command execution.
4
What software versions are affected by CVE-2021-43711?
The vulnerability affects Totolink EX200 Firmware version 4.0.3c.7646_B20201211.
5
Is authentication required for exploiting CVE-2021-43711?
No, the vulnerability allows for unauthenticated command execution.