TOTOLINK A860R V4.1.2cu.5182B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.
In TOTOLINK A860R V4.1.2cu.5182B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vulnerability.
In TOTOLINK A860R V4.1.2cu.5182B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability.
TOTOLINK A860R V4.1.2cu.5182B20201027 is vulnerable to Buffer Overflow via Cstecgi.cgi.
In TOTOLINK A860R V4.1.2cu.5182B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for execution without filtering, resulting in a command injection vulnerability.
TOTOLink A860R V4.1.2cu.5182B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERYSTRING parameter.