References https://nvd.nist.gov/vuln/detail/cve-2022-27003 https://www.nsfocus.net/vulndb/63643 https://github.com/wudipjq/my_vuln/blob/main/totolink/vuln_32/32.md https://advisories.checkpoint.com/defense/advisories/public/2022/cpai-2022-0864.html https://app.opencve.io/cve/?page=55&vendor=totolink https://vulners.com/circl/CIRCL:CVE-2022-28935 https://www.reddit.com/r/pwnhub/comments/1t0su4o/critical_command_injection_vulnerability_found_in/ https://thrive.trellix.com/s/article/000013859 https://socradar.io/free-tools/cve-radar/CVE-2022-27003 https://www.fortiguard.com/encyclopedia/fct-app/51515
Related VulnerabilitiesTOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞PoCCVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information DisclosurePoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-42887: TOTOLINK EX1200T 4.1.2cu.5215 - Authentication BypassPoCCVE-2022-25082: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-30013: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-46574: TOTOLINK A3700R - Command InjectionPoCCVE-2024-24328: TotoLink Router setMacFilterRules - Command InjectionPoCCVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection