CVE-2021-44247
04.02.2022, 02:15
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.
Vendor | Product | Version |
---|---|---|
totolink | a720r_firmware | 4.1.5cu.470_b20200911:cu.470_b20200911 |
totolink | a830r_firmware | 5.9c.4729_b20191112:c.4729_b20191112 |
totolink | a3100r_firmware | 4.1.2cu.5050_b20200504:cu.5050_b20200504 |
𝑥
= Vulnerable software versions