漏洞描述 TOTOLINK是亚太区中高端无线路由的一个品牌,韩国市场占有率达82.3%,2005年在深圳成立深圳众唐科技有限公司,负责产品的研发、制造与中国地区市场销售。该产品T10固件及其他固件存在远程命令执行漏洞,攻击者可通过该漏洞执行任意系统命令。
相关漏洞推荐 POC CVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command Injection POC CVE-2021-42887: TOTOLINK EX1200T 4.1.2cu.5215 - Authentication Bypass POC CVE-2022-25082: TOTOLink - Unauthenticated Command Injection POC CVE-2023-30013: TOTOLink - Unauthenticated Command Injection POC CVE-2023-46574: TOTOLINK A3700R - Command Injection POC CVE-2024-24328: TotoLink Router setMacFilterRules - Command Injection POC CVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection POC CVE-2024-34257: TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection POC CVE-2024-51228: TOTOLINK CX-A3002RU - Remote Code Execution POC CVE-2024-7332: TOTOLINK CP450 v4.1.0cu.747_B20191224 - Hard-Coded Password Vulnerability POC CVE-2022-25084: TOTOLink T6 V5.9c.4085_B20190428 Command Injection POC CVE-2023-46574: TOTOLINK A3700R存在RCE漏洞 POC CVE-2024-51228: TOTOLINK CX-A3002RU RCE