First published: Wed Mar 30 2022(Updated: )
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3100R Firmware | =5.9c.4577 | |
Totolink A3100R Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46007 is considered to be of medium severity due to its potential for remote command injection.
To fix CVE-2021-46007, update the Totolink A3100R firmware to a version that addresses the command injection vulnerability.
CVE-2021-46007 can be exploited through command injection attacks that allow an attacker to execute arbitrary system commands on the device.
CVE-2021-46007 affects the Totolink A3100R running firmware version 5.9c.4577.
A possible workaround for CVE-2021-46007 is to restrict access to the affected backend service until a firmware update can be applied.