A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.017
                        
                    
                    
                        
                            EPSS Ranking 81.7%