CVE-2022-25135: Command Injection
Published Feb 18, 2022
·Updated
A command injection vulnerability in the function recvmeshinfosync of TOTOLINK Technology router T6 V3Firmware T6V3V4.1.5cu.748B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Affected Software
2 affected components
TOTOLINK T6 Firmware=v4.1.5cu.748_b20211015
TOTOLINK T6
Event History
Feb 18, 2022
CVE Published
via MITRE·11:09 PM
Data Sourced
via MITRE·11:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25135?
CVE-2022-25135 is classified as a high-severity command injection vulnerability.
2
How do I fix CVE-2022-25135?
To mitigate CVE-2022-25135, update the firmware of the TOTOLINK T6 router to the latest version.
3
What impact does CVE-2022-25135 have on the TOTOLINK T6 router?
CVE-2022-25135 allows attackers to execute arbitrary commands on the router remotely.
4
Which versions of the TOTOLINK T6 firmware are affected by CVE-2022-25135?
CVE-2022-25135 affects TOTOLINK T6 firmware version v4.1.5cu.748_b20211015.
5
What type of attack does CVE-2022-25135 facilitate?
CVE-2022-25135 enables attackers to leverage crafted MQTT packets for command injection attacks.