skeetabc/CVE-TOTOLINK-A800R

skeetabc/CVE-TOTOLINK-A800R

Releases0
TOTOLINK A800R V5.9c.681 Multiple Vulnerabilities (Auth Bypass + RCE + Info Disclosure)

CVE History

CVEPublishedCVSS v3CVSS v2
7.3 HIGH7.5 HIGH

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used.