2 results (0.006 seconds)

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 1

TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. • https://sedate-class-393.notion.site/TOTOlink-ee7eb0d4cd5d43e9983296200371eff1?pvs=4 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 1

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function. • http://totolink.com https://github.com/JeeseenSec/Report/tree/main/TOTOLINK%2CThanks https://github.com/JeeseenSec/Report/tree/main/TOTOLINK/CVE-2023-31569 https://www.totolink.net/home/menu/newstpl/menu_newstpl/products/id/218.html • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •