CVE-2021-27708
Last modified
CVE-2021-27708 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. EPSS estimates a 7.61% chance of exploitation in the next 30 days.
Description
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "command" parameter is directly passed to the attacker, allowing them to control the "command" field to attack the OS.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Totolink | X5000r Firmware | 9.1.0u.6118_b20201102 |
| Totolink | A720r Firmware | 4.1.5cu.470_b20200911 |
References
- https://hackmd.io/7FtB06f-SJ-SCfkMYcXYxAExploit, Third Party Advisory
- https://hackmd.io/mDgIBvoxSPCZrZiZjfQGhwExploit, Third Party Advisory
- https://hackmd.io/7FtB06f-SJ-SCfkMYcXYxAExploit, Third Party Advisory
- https://hackmd.io/mDgIBvoxSPCZrZiZjfQGhwExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-27708?
How severe is CVE-2021-27708?
How do I fix CVE-2021-27708?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-27702Sercomm Router Etisalat Model S3- AC2100 is affected by Inco…7.3
- CVE-2021-27703Sercomm Model Etisalat Model S3- AC2100 is affected by Cross…5.4
- CVE-2021-27704Appspace 6.2.4 is affected by Incorrect Access Control via t…6.5
- CVE-2021-27705Buffer Overflow in Tenda G1 and G3 routers with firmware v15…9.8
- CVE-2021-27706Buffer Overflow in Tenda G1 and G3 routers with firmware ver…9.8
- CVE-2021-27707Buffer Overflow in Tenda G1 and G3 routers with firmware v15…9.8
- CVE-2021-27710Command Injection in TOTOLINK X5000R router with firmware v9…9.8
- CVE-2021-27715An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 …9.8
- CVE-2021-27722An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5.…5.5
- CVE-2021-27723Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-27730Accellion FTA 9_12_432 and earlier is affected by argument i…9.8
- CVE-2021-27731Accellion FTA 9_12_432 and earlier is affected by stored XSS…6.1
Are you affected by CVE-2021-27708?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
