References https://nvd.nist.gov/vuln/detail/CVE-2021-43711 https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33636 https://github.com/doudoudedi/ToTolink_EX200_Cmmand_Execute/blob/main/ToTolink%20EX200%20Comand%20Injection2.md https://advisories.checkpoint.com/defense/advisories/public/2022/cpai-2021-1095.html/ https://avd.aliyun.com/detail?id=AVD-2021-43711 https://cve.circl.lu/vuln/CVE-2021-43711 https://github.com/advisories/ghsa-chwf-9c6x-wv85 https://www.cybersecurity-help.cz/vdb/SB2022031414 https://cve.imfht.com/detail/CVE-2021-43711 https://www.venustech.com.cn/new_type/mzsjgg/20220315/23566.html https://attilaszia/linux-iot-cves
Related VulnerabilitiesTOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞PoCCVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information DisclosurePoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-42887: TOTOLINK EX1200T 4.1.2cu.5215 - Authentication BypassPoCCVE-2022-25082: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-30013: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-46574: TOTOLINK A3700R - Command InjectionPoCCVE-2024-24328: TotoLink Router setMacFilterRules - Command InjectionPoCCVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection