First published: Fri Feb 04 2022(Updated: )
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink X5000r Firmware | =9.1.0u.6118_b20201102 | |
TOTOLINK X5000R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45738 is a command injection vulnerability discovered in TOTOLINK X5000R v9.1.0u.6118_B20201102.
The command injection vulnerability in TOTOLINK X5000R v9.1.0u.6118_B20201102 allows attackers to execute arbitrary commands by exploiting the UploadFirmwareFile function and the FileName parameter.
The severity of CVE-2021-45738 is critical with a CVSS score of 9.8.
TOTOLINK X5000R v9.1.0u.6118_B20201102 is affected by CVE-2021-45738.
Patch or update the TOTOLINK X5000R firmware to a non-vulnerable version.