First published: Fri Feb 04 2022(Updated: )
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A720r Firmware | =4.1.5cu.470_b20200911 | |
TOTOLINK A720R | ||
Totolink A830r Firmware | =5.9c.4729_b20191112 | |
Totolink A830R | ||
Totolink A3100r Firmware | =4.1.2cu.5050_b20200504 | |
TOTOLink A3100R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44247 is a command injection vulnerability found in Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911.
CVE-2021-44247 has a severity rating of 9.8 (Critical).
Totolink A3100r Firmware version 4.1.2cu.5050_b20200504, Totolink A830r Firmware version 5.9c.4729_b20191112, and Totolink A720r Firmware version 4.1.5cu.470_b20200911 are affected by CVE-2021-44247.
An attacker can exploit CVE-2021-44247 by sending a specially crafted IpFrom parameter, allowing them to execute arbitrary commands on the vulnerable Totolink devices.
At the moment, there is no information regarding an official fix for CVE-2021-44247. It is recommended to follow the vendor's security advisories for updates.