Lucene search

K
cveMitreCVE-2021-44247
HistoryFeb 04, 2022 - 2:15 a.m.

CVE-2021-44247

2022-02-0402:15:07
CWE-77
mitre
web.nvd.nist.gov
43
totolink
devices
command injection
vulnerability
setnoticecfg function
ipfrom parameter
security
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.011

Percentile

84.4%

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.

Affected configurations

Nvd
Node
totolinka720r_firmwareMatch4.1.5cu.470_b20200911
AND
totolinka720rMatch-
Node
totolinka830r_firmwareMatch5.9c.4729_b20191112
AND
totolinka830rMatch-
Node
totolinka3100r_firmwareMatch4.1.2cu.5050_b20200504
AND
totolinka3100rMatch-
VendorProductVersionCPE
totolinka720r_firmware4.1.5cu.470_b20200911cpe:2.3:o:totolink:a720r_firmware:4.1.5cu.470_b20200911:*:*:*:*:*:*:*
totolinka720r-cpe:2.3:h:totolink:a720r:-:*:*:*:*:*:*:*
totolinka830r_firmware5.9c.4729_b20191112cpe:2.3:o:totolink:a830r_firmware:5.9c.4729_b20191112:*:*:*:*:*:*:*
totolinka830r-cpe:2.3:h:totolink:a830r:-:*:*:*:*:*:*:*
totolinka3100r_firmware4.1.2cu.5050_b20200504cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5050_b20200504:*:*:*:*:*:*:*
totolinka3100r-cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.011

Percentile

84.4%

Related for CVE-2021-44247