A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
| Software | From | Fixed in |
|---|---|---|
| totolink / a7000r_firmware | 4.1cu.4154 | 4.1cu.4154.x |