Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-27708

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "command" parameter is directly passed to the attacker, allowing them to control the "command" field to attack the OS.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.202
EPSS Ranking 95.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2021-27708
  • Totolink » A720r » Version: N/A
    cpe:2.3:h:totolink:a720r:-
  • Totolink » X5000r » Version: N/A
    cpe:2.3:h:totolink:x5000r:-
  • Totolink » A720r Firmware » Version: 4.1.5cu.470_b20200911
    cpe:2.3:o:totolink:a720r_firmware:4.1.5cu.470_b20200911
  • Totolink » X5000r Firmware » Version: 9.1.0u.6118_b20201102
    cpe:2.3:o:totolink:x5000r_firmware:9.1.0u.6118_b20201102


Contact Us

Shodan ® - All rights reserved