Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter
Published Mar 15, 2022
9.8
CRITICALCVSS 3.1
EPSS 5.46%
Description
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected products
No data.
Configuration 1
- 9.1.0u.6118_b20201102
Configuration 2
- 9.1.0u.6115_b20201022
-
- Version 9.1.0u.6115_b20201022StatusaffectedConstraints-
- Version
-
- Version 9.1.0u.6118_b20201102StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TOTOLINK | A7000r Firmware | n/a |
| ||||||
| TOTOLINK | X5000r Firmware | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CISA ADP) ▾
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 12, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 5.46% (0.05455) | 92.50th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.51% (0.05508) | 91.75th | v5 (v2026.06.15) |
| Mar 30, 2025 | 46.71% (0.46705) | 97.42th | v4 (v2025.03.14) |
| Mar 29, 2025 | 72.25% (0.72248) | 98.35th | v4 (v2025.03.14) |
| Mar 25, 2025 | 46.71% (0.46705) | 97.41th | v4 (v2025.03.14) |
| Mar 24, 2025 | 41.46% (0.41456) | 97.11th | v4 (v2025.03.14) |
| Mar 23, 2025 | 64.77% (0.64770) | 98.29th | v4 (v2025.03.14) |
| Mar 22, 2025 | 27.17% (0.27168) | 95.98th | v4 (v2025.03.14) |
| Mar 19, 2025 | 20.03% (0.20030) | 94.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.46% (0.07457) | 91.11th | v4 (v2025.03.14) |
| Mar 3, 2025 | 2.19% (0.02194) | 89.34th | v3 (v2023.03.01) |
| Dec 12, 2024 | 0.64% (0.00643) | 79.95th | v3 (v2023.03.01) |
| Sep 13, 2024 | 0.98% (0.00978) | 83.77th | v3 (v2023.03.01) |
| Aug 27, 2024 | 8.90% (0.08897) | 94.69th | v3 (v2023.03.01) |
| Oct 6, 2023 | 11.57% (0.11573) | 94.60th | v3 (v2023.03.01) |
| Aug 26, 2023 | 10.49% (0.10486) | 94.27th | v3 (v2023.03.01) |
| Apr 17, 2023 | 18.69% (0.18694) | 95.45th | v3 (v2023.03.01) |
| Mar 22, 2023 | 22.65% (0.22650) | 95.74th | v3 (v2023.03.01) |
| Mar 7, 2023 | 16.87% (0.16867) | 95.16th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.05% (0.02055) | 79.82th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.05% (0.02055) | 77.90th | v2 (v2022.01.01) |
| Mar 23, 2022 | 2.05% (0.02055) | 57.42th | v2 (v2022.01.01) |
| Mar 16, 2022 | 1.00% (0.01005) | 18.71th | v2 (v2022.01.01) |
References (1)
- https://github.com/wudipjq/my_vuln/blob/main/totolink/vuln_30/30.md x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/totolink/vuln_30/30.md | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.