Impact
Command injection is possible in the getCurrentTime function of /cgi-bin/cstecgi.cgi when the ntp_server argument is manipulated. The flaw allows an attacker to inject and execute arbitrary commands on the router’s operating system, compromising confidentiality, integrity, and availability of the device and potentially the networks it serves.
Affected Systems
The vulnerability affects TOTOLINK N600R routers running firmware 4.3.0cu.7647_B20210106. No other affected versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the exploit is publicly available with no reported exploitation restrictions. Remote attackers can leverage the injection without local access. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but its public exploit and remote nature increase its threat posture.
OpenCVE Enrichment