Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Totolink N300RH cstecgi.cgi setUploadSetting file inclusion
Vulnerability Description
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
TOTOLINK N300RH 安全漏洞
Vulnerability Description
TOTOLINK N300RH是中国吉翁电子(TOTOLINK)公司的一款长距离无线路由器。 TOTOLINK N300RH 6.1c.1353_B20190305版本存在安全漏洞,该漏洞源于/cgi-bin/cstecgi.cgi文件中setUploadSetting函数对参数FileName的操作,可能导致文件包含。
CVSS Information
N/A
Vulnerability Type
N/A