AI Score
Confidence
High
EPSS
Percentile
48.3%
SSVC
Exploitation
poc
Automatable
no
Technical Impact
total
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
[
{
"cpes": [
"cpe:2.3:h:totolink:x5000r:-:*:*:*:*:*:*:*"
],
"vendor": "totolink",
"product": "x5000r",
"versions": [
{
"status": "affected",
"version": "v9.1.0cu.2350_b20230313"
}
],
"defaultStatus": "unknown"
}
]