vendor:
Routers, wifi access points and network devices
by:
Pierre Kim
9.8
CVSS
HIGH
Backdoor and Remote Code Execution
284
CWE
Product Name: Routers, wifi access points and network devices
Affected Version From: TOTOLINK-A850R-V1.0.1-B20150707.1612.web
Affected Version To: TOTOLINK-N300RT-V2.1.1-B20150708.1613.web
Patch Exists: Yes
Related CWE: No current CVE
CPE: h:totolink:a850r_v1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Backdoor and RCE found in 8 TOTOLINK router models
A backdoor is present in several TOTOLINK products. This was confirmed by analysing the latest firmwares and by testing the backdoor against live routers. At least 8 TOTOLINK products are affected (firmwares come from totolink.net and from totolink.cn). By sending a crafted request to the WAN IP, an attacker will open the HTTP remote management interface on the Internet. Then an attacker can use a Remote Code Execution in the HTTP remote management interface by using the hidden /boafrm/formSysCmd form, bypassing the authentication system.
Mitigation:
Update to the latest firmware version available from the vendor.