Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-87950
HistoryOct 10, 2022 - 12:00 a.m.

TOTOLINK NR1800X UploadFirmwareFile Command Injection Vulnerability

2022-10-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
totolink nr1800x
command injection
uploadfirmwarefile
vulnerability
china gion electronics
arbitrary command execution
cgi file

EPSS

0.449

Percentile

97.4%

TOTOLINK NR1800X is an excellent 5G NR indoor Wi-Fi and SIP CPE from China Gion Electronics (TOTOLINK).Designed to provide fast and convenient deployment of NR fixed data services for homes and offices.A command injection vulnerability exists in TOTOLINK NR1800X V9.1.0u.6279_B20210910 version, which originates from the /cgi- bin/cstecgi.cgi file UploadFirmwareFile function in the FileName parameter fails to properly filter the construct command special characters, commands, and so on. An attacker could exploit the vulnerability to cause arbitrary command execution.

EPSS

0.449

Percentile

97.4%

Related for CNVD-2022-87950