First published: Tue Feb 22 2022(Updated: )
TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A3000ru Firmware | =v5.9c.2280_b20180512 | |
TOTOLink A3000RU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25075 is a command injection vulnerability found in TOTOLink A3000RU V5.9c.2280_B20180512 firmware.
CVE-2022-25075 allows attackers to execute arbitrary commands on TOTOLink A3000RU routers via the QUERY_STRING parameter.
CVE-2022-25075 has a severity rating of 9.8 (Critical).
To fix CVE-2022-25075, it is recommended to update to a patched version of TOTOLink A3000RU firmware.
You can find more information about CVE-2022-25075 at the following link: [link](https://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/A3000RU/README.md)