TOTOLink Vulnerability Key Information Vendor: TOTOLink Product: CA300 PoE Version: V6.2c-884 Type: Remote Command Execution Author: Jian Peng Institution: pengjiaqian@nie.ac.cn Vulnerability Description A Command Injection vulnerability was found in the TOTOLink router with firmware version V6.2c-884, allowing remote attackers to execute arbitrary OS commands via a crafted request. Remote Command Execution In binary: In function, is directly passed by the attacker, enabling control over to attack the OS. The initial input is extracted and causes command injection. Proof of Concept (PoC) To exploit this vulnerability, set as , and the router will execute it: Result Executing the above PoC results in obtaining a shell: