- Description
 - Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
 - Source
 - cve@mitre.org
 - NVD status
 - Analyzed
 - Products
 - x5000r_firmware
 
CVSS 3.1
- Type
 - Secondary
 - Base score
 - 6.5
 - Impact score
 - 2.5
 - Exploitability score
 - 3.9
 - Vector string
 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
 - Severity
 - MEDIUM
 
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
 - CWE-77
 
- Hype score
 - Not currently trending
 
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:o:totolink:x5000r_firmware:9.1.0u.6369_b20230113:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "FAA27C60-0FFD-45E3-91B1-0C2F8EBF2442"
          }
        ],
        "operator": "OR"
      },
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:h:totolink:x5000r:-:*:*:*:*:*:*:*",
            "vulnerable": false,
            "matchCriteriaId": "BC45BFB0-0CF0-4F9E-B19D-D274B17F1591"
          }
        ],
        "operator": "OR"
      }
    ],
    "operator": "AND"
  }
]