Description
A security vulnerability has been detected in Totolink WA300 5.2cu.7112_B20190227. This affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument hostTime leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CVSS 6.3EPSS 0.9159999999999999%Risk 0.68
View source- Published
- 2026-05-04 03:16:12
- Affected versions
- unknown
- Type
- Firmware
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L