Impact
The vulnerability allows a remote attacker to execute arbitrary shell commands on the router through the NTPSyncWithHost function in the /cgi-bin/cstecgi.cgi script. By manipulating the host_time argument, the injected payload is run with system privileges, resulting in full control over the device's operating system. This leads to a remote code execution scenario that can compromise confidentiality, integrity, and availability of the network and data processed by the router.
Affected Systems
Totolink NR1800X routers running firmware version 9.1.0u.6279_B20210910 are affected. Only this specific firmware build is listed as vulnerable; newer or older revisions may not exhibit the same weakness.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of 4% suggests a low to moderate likelihood of exploitation. The vulnerability is not catalogued in CISA KEV, but the public disclosure and available exploit mean that any entity with access to the router’s Telnet service can trigger the injection remotely. Successful exploitation would grant attackers control over the device and potentially the entire network it supports.
OpenCVE Enrichment