TOTOLink Vulnerability Vendor: TOTOLink Product: A3006 PoE Version: V6.2tc.884 Type: Remote Command Execution Author: Jianqian Peng Institution: pengjianqian@lie.ac.cn Vulnerability Description Remote Command Execution in upgrade.bin binary: - In function, is directly passed by the attacker, allowing control of to attack the OS. - The initial input will be extracted and cause command injection. Code Snippet: PoC: - This will execute a shell on the router. Result: - Successfully obtained a shell with root privileges.