Vulnerability Details CVE-2021-43711
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.138
EPSS Ranking 94.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-43711
-
cpe:2.3:h:totolink:ex200:-
-
cpe:2.3:o:totolink:ex200_firmware:4.0.3c.7646_b20201211