CRITICAL

CVE-2021-44247

CVSS v3

9.8

CRITICAL

EPSS Score

26.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.

Technical details

Published
2/4/2022

Frequently asked questions

What is CVE-2021-44247?

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.

Is CVE-2021-44247 actively exploited?

Active exploitation of CVE-2021-44247 has not been confirmed. The EPSS score is 26.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-44247?

CVE-2021-44247 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-44247 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.