CVE-2022-25080: OS Command Injection
Published Feb 22, 2022
·Updated
TOTOLink A830R V5.9c.4729B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERYSTRING parameter.
Affected Software
2 affected components
TOTOLINK A830r Firmware=5.9c.4729_b20191112
TOTOLINK A830R
Remediation
Event History
Feb 22, 2022
CVE Published
via MITRE·10:44 PM
Data Sourced
via MITRE·10:44 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25080?
CVE-2022-25080 refers to a command injection vulnerability in the "Main" function of TOTOLink A830R V5.9c.4729_B20191112.
2
How severe is CVE-2022-25080?
CVE-2022-25080 has a severity rating of critical with a score of 9.8 out of 10.
3
How does CVE-2022-25080 impact TOTOLink A830R V5.9c.4729_B20191112?
CVE-2022-25080 allows attackers to execute arbitrary commands via the QUERY_STRING parameter, posing a high risk to the security of the affected device.
4
What is the affected software version of TOTOLink A830R?
TOTOLink A830R V5.9c.4729_B20191112 is the affected software version.
5
Is TOTOLink A830R V5.9c.4729_B20191112 vulnerable to the command injection vulnerability?
Yes, TOTOLink A830R V5.9c.4729_B20191112 is vulnerable to the command injection vulnerability.