CVE-2021-44247
published 2022-02-04CVE-2021-44247: Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | a3100r_firmware | — | — |
| totolink | a720r_firmware | — | — |
| totolink | a830r_firmware | — | — |