CVE-2022-25075: OS Command Injection
TOTOLink A3000RU V5.9c.2280B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERYSTRING parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-25075?
CVE-2022-25075 is a command injection vulnerability found in TOTOLink A3000RU V5.9c.2280_B20180512 firmware.
How does CVE-2022-25075 impact TOTOLink A3000RU?
CVE-2022-25075 allows attackers to execute arbitrary commands on TOTOLink A3000RU routers via the QUERY_STRING parameter.
What is the severity rating of CVE-2022-25075?
CVE-2022-25075 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-25075?
To fix CVE-2022-25075, it is recommended to update to a patched version of TOTOLink A3000RU firmware.
Where can I find more information about CVE-2022-25075?
You can find more information about CVE-2022-25075 at the following link: [link](https://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/A3000RU/README.md)