CVE-2022-26186: Command Injection
Published Mar 22, 2022
·Updated
TOTOLINK N600R V4.3.0cu.7570B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.
Affected Software
2 affected components
TOTOLINK N600R firmware=4.3.0cu.7570_b20200620
TOTOLINK N600R
Event History
Mar 22, 2022
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-26186?
The severity of CVE-2022-26186 is critical with a severity value of 9.8.
2
What software is affected by CVE-2022-26186?
TOTOLINK N600R V4.3.0cu.7570_B20200620 firmware is affected by CVE-2022-26186.
3
How does CVE-2022-26186 work?
CVE-2022-26186 is a command injection vulnerability that can be exploited via the exportOvpn interface at cstecgi.cgi in TOTOLINK N600R firmware.
4
Is TOTOLINK N600R vulnerable to CVE-2022-26186?
Yes, TOTOLINK N600R V4.3.0cu.7570_B20200620 firmware is vulnerable to CVE-2022-26186.
5
How can I fix CVE-2022-26186?
There is currently no official fix available for CVE-2022-26186. It is recommended to apply any patches or updates provided by the vendor when they become available.