Lucene search

K
cveMitreCVE-2021-27708
HistoryApr 14, 2021 - 4:15 p.m.

CVE-2021-27708

2021-04-1416:15:14
CWE-78
mitre
web.nvd.nist.gov
26
4
totolink
x5000r
a720r
router
firmware
command injection
cve-2021-27708
nvd
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.03

Percentile

91.1%

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc’s system function with untrusted input. In the function, “command” parameter is directly passed to the attacker, allowing them to control the “command” field to attack the OS.

Affected configurations

Nvd
Node
totolinkx5000rMatch-
AND
totolinkx5000r_firmwareMatch9.1.0u.6118_b20201102
Node
totolinka720rMatch-
AND
totolinka720r_firmwareMatch4.1.5cu.470_b20200911
VendorProductVersionCPE
totolinkx5000r-cpe:2.3:h:totolink:x5000r:-:*:*:*:*:*:*:*
totolinkx5000r_firmware9.1.0u.6118_b20201102cpe:2.3:o:totolink:x5000r_firmware:9.1.0u.6118_b20201102:*:*:*:*:*:*:*
totolinka720r-cpe:2.3:h:totolink:a720r:-:*:*:*:*:*:*:*
totolinka720r_firmware4.1.5cu.470_b20200911cpe:2.3:o:totolink:a720r_firmware:4.1.5cu.470_b20200911:*:*:*:*:*:*:*

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.03

Percentile

91.1%

Related for CVE-2021-27708