First published: Tue Feb 22 2022(Updated: )
TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A830r Firmware | =5.9c.4729_b20191112 | |
Totolink A830R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25080 refers to a command injection vulnerability in the "Main" function of TOTOLink A830R V5.9c.4729_B20191112.
CVE-2022-25080 has a severity rating of critical with a score of 9.8 out of 10.
CVE-2022-25080 allows attackers to execute arbitrary commands via the QUERY_STRING parameter, posing a high risk to the security of the affected device.
TOTOLink A830R V5.9c.4729_B20191112 is the affected software version.
Yes, TOTOLink A830R V5.9c.4729_B20191112 is vulnerable to the command injection vulnerability.