10

CVE-2015-9551

Exploit

An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sysCmd parameter.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TotolinkA850r-v1 Firmware Version < 1.0.1-b20150707.1612
   TotolinkA850r-v1 Version-
TotolinkF1-v2 Firmware Version < 2.1.1-b20150708.1646
   TotolinkF1-v2 Version-
TotolinkF2-v1 Firmware Version < 2.1.0-b20150320.1611
   TotolinkF2-v1 Version-
TotolinkN150rt-v2 Firmware Version < 2.1.1-b20150708.1548
   TotolinkN150rt-v2 Version-
TotolinkN151rt-v2 Firmware Version < 1.1-b20150708.1559
   TotolinkN151rt-v2 Version-
TotolinkN300rh-v2 Firmware Version < 2.0.1-b20150708.1625
   TotolinkN300rh-v2 Version-
TotolinkN300rh-v3 Firmware Version < 3.0.0-b20150331.0858
   TotolinkN300rh-v3 Version-
TotolinkN300rt-v2 Firmware Version < 2.1.1-b20150708.1613
   TotolinkN300rt-v2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.37% 0.908
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C