cve/2021/CVE-2021-46007.md

18 lines
691 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-46007](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46007)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.
### POC
#### Reference
- https://hackmd.io/t_nRWxS2Q2O7GV2E5BhQMg
#### Github
No PoCs found on GitHub currently.