Impact
The vulnerable setUssd command allows an attacker to inject arbitrary shell commands into the operating system of the TOTOLINK NR1800X router when the ussd argument is not properly validated. This flaw permits the execution of malicious code, potentially compromising the confidentiality, integrity, and availability of the device and any connected networks.
Affected Systems
Products affected are TOTOLINK NR1800X routers running firmware version 9.1.0u.6681_B20230703. The flaw resides in the cstecgi.cgi executable exposed via the web interface.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. However, the attack can be carried out remotely with publicly available exploit code, making the risk moderate but significant enough to warrant timely remediation.
OpenCVE Enrichment