Impact
The vulnerability is a command injection flaw located in the system.setclock interface of several router firmware versions. A crafted request to this interface allows an attacker to execute arbitrary shell commands with root privileges, potentially compromising system confidentiality, integrity, and availability. The flaw can be used by any user capable of sending input to the vulnerable endpoint, whether connected from the local network or the Internet.
Affected Systems
The affected firmware includes TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15. All devices run firmware supplied by the referenced vendor and expose the vulnerable system.setclock endpoint.
Risk and Exploitability
The EPSS score of 3% indicates a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the router's management interface, which can be reached from the internal network or the Internet. An attacker who controls this interface could exploit the flaw without additional privileges, making it a critical concern for exposed devices.
OpenCVE Enrichment