CVE-2022-25133: Command Injection
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3Firmware T6V3V4.1.5cu.748B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25133?
CVE-2022-25133 is considered a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2022-25133?
To mitigate CVE-2022-25133, users should update their TOTOLINK T6 router firmware to the latest version provided by the manufacturer.
Which devices are impacted by CVE-2022-25133?
CVE-2022-25133 affects the TOTOLINK T6 router running firmware version v4.1.5cu.748_B20211015.
What kind of attack is possible with CVE-2022-25133?
CVE-2022-25133 allows attackers to execute arbitrary commands on the device via a crafted MQTT packet.
Is there a workaround for CVE-2022-25133?
There is no official workaround for CVE-2022-25133, making a firmware update the recommended action for users.