CVE-2022-25076: OS Command Injection
Published Feb 22, 2022
·Updated
TOTOLink A800R V4.1.2cu.5137B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERYSTRING parameter.
Affected Software
2 affected components
TOTOLINK A800r Firmware=v4.1.2cu.5137_b20200730
TOTOLINK A800R
Remediation
Event History
Feb 22, 2022
CVE Published
via MITRE·10:44 PM
Data Sourced
via MITRE·10:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25076?
The severity of CVE-2022-25076 is critical with a CVSS score of 9.8.
2
How does CVE-2022-25076 impact TOTOLink A800R V4.1.2cu.5137_B20200730?
CVE-2022-25076 allows attackers to execute arbitrary commands on TOTOLink A800R V4.1.2cu.5137_B20200730 by exploiting a command injection vulnerability.
3
Which software versions are affected by CVE-2022-25076?
TOTOLink A800R firmware version v4.1.2cu.5137_b20200730 is affected by CVE-2022-25076.
4
How can the command injection vulnerability in TOTOLink A800R V4.1.2cu.5137_B20200730 be exploited?
Attackers can exploit the command injection vulnerability in TOTOLink A800R V4.1.2cu.5137_B20200730 by manipulating the QUERY_STRING parameter to execute arbitrary commands.
5
What is the CWE ID associated with CVE-2022-25076?
CVE-2022-25076 is associated with CWE IDs 77 and 78.