The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:03:08.672Z
Reserved: 2021-11-15T00:00:00
Link: CVE-2021-43711
No data.
Status : Modified
Published: 2022-01-04T14:15:08.127
Modified: 2024-11-21T06:29:39.840
Link: CVE-2021-43711
No data.
OpenCVE Enrichment
No data.
Weaknesses