Showing 1 vulnerability on this page for n301rt_firmware

Signals CISA KEV Ransomware Nuclei
totolink vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

totolink a3002ru Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.

CWE-78Jan 27, 20201 related artifact
CVSS8.8v3.1EPSS25.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX