CVE-2021-27708
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "command" parameter is directly passed to the attacker, allowing them to control the "command" field to attack the OS.
Una inyección de comandos en el enrutador TOTOLINK X5000R con firmware v9.1.0u.6118_B20201102, permite a atacantes remotos ejecutar comandos arbitrarios del Sistema Operativo mediante el envío de una petición HTTP modificada. Esto ocurre porque la función ejecuta la función del sistema de glibc con una entrada que no es confiable. En la función, el parámetro "command" se pasa directamente al atacante, lo que le permite controlar el campo "command" para atacar el sistema operativo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-02-25 CVE Reserved
- 2021-04-14 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://hackmd.io/7FtB06f-SJ-SCfkMYcXYxA | 2024-08-03 | |
https://hackmd.io/mDgIBvoxSPCZrZiZjfQGhw | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Totolink Search vendor "Totolink" | X5000r Firmware Search vendor "Totolink" for product "X5000r Firmware" | 9.1.0u.6118_b20201102 Search vendor "Totolink" for product "X5000r Firmware" and version "9.1.0u.6118_b20201102" | - |
Affected
| in | Totolink Search vendor "Totolink" | X5000r Search vendor "Totolink" for product "X5000r" | - | - |
Safe
|
Totolink Search vendor "Totolink" | A720r Firmware Search vendor "Totolink" for product "A720r Firmware" | 4.1.5cu.470_b20200911 Search vendor "Totolink" for product "A720r Firmware" and version "4.1.5cu.470_b20200911" | - |
Affected
| in | Totolink Search vendor "Totolink" | A720r Search vendor "Totolink" for product "A720r" | - | - |
Safe
|