The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges. (CVSS:7.2) (Last Update:2023-07-10 16:21:27) Latest security vulnerabilities (File Inclusion) (CVSS score >= 4)
TOTOLINK Wireless Routers Remote Command Execution
Multiple TOTOLINK network products contain a command injection vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the command parameter. After