CVE-2021-45742: Command Injection
Published Feb 4, 2022
·Updated
TOTOLINK A720R v4.1.5cu.470B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERYSTRING parameter.
Affected Software
2 affected components
TOTOLINK A720r Firmware=4.1.5cu.470_b20200911
TOTOLINK A720R
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-45742?
The severity of CVE-2021-45742 is critical.
2
What is the affected software for CVE-2021-45742?
The affected software for CVE-2021-45742 is Totolink A720r Firmware version 4.1.5cu.470_b20200911.
3
How does CVE-2021-45742 impact the system?
CVE-2021-45742 allows attackers to execute arbitrary commands via the QUERY_STRING parameter, posing a significant security risk.
4
Is TOTOLINK A720R version 4.1.5cu.470_B20200911 vulnerable to CVE-2021-45742?
Yes, TOTOLINK A720R version 4.1.5cu.470_B20200911 is vulnerable to CVE-2021-45742.
5
How can I fix CVE-2021-45742?
To fix CVE-2021-45742, it is recommended to update to a patched version of Totolink A720r firmware.