CVE-2022-25084: OS Command Injection
Published Feb 22, 2022
·Updated
TOTOLink T6 V5.9c.4085B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERYSTRING parameter.
Affected Software
2 affected components
TOTOLINK T6 Firmware=5.9c.4085_b20190428
TOTOLINK T6
Remediation
Event History
Feb 22, 2022
CVE Published
via MITRE·10:44 PM
Data Sourced
via MITRE·10:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25084?
CVE-2022-25084 has been classified as a high severity vulnerability due to its potential for arbitrary command execution.
2
How do I fix CVE-2022-25084?
To fix CVE-2022-25084, update the TOTOLink T6 firmware to a version that addresses this command injection vulnerability.
3
What devices are affected by CVE-2022-25084?
CVE-2022-25084 affects the TOTOLink T6 running firmware version 5.9c.4085_B20190428.
4
What type of vulnerability is CVE-2022-25084?
CVE-2022-25084 is identified as a command injection vulnerability impacting the 'Main' function of the firmware.
5
Can CVE-2022-25084 be exploited remotely?
Yes, CVE-2022-25084 can potentially be exploited remotely through the QUERY_STRING parameter.