Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TotoLink A3002RU 操作系统命令注入漏洞
Vulnerability Description
TotoLink A3002RU是中国台湾吉翁电子(TotoLink)公司的一款无线路由器产品。 TotoLink A3002RU 1.0.8版本中的fromNtp存在操作系统命令注入漏洞。攻击者可借助‘ntpServerIp2’POST参数利用该漏洞执行系统命令。
CVSS Information
N/A
Vulnerability Type
N/A