CVE-2022-26188: Command Injection
Published Mar 22, 2022
·Updated
TOTOLINK N600R V4.3.0cu.7570B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.
Affected Software
2 affected components
TOTOLINK N600R firmware=4.3.0cu.7570_b20200620
TOTOLINK N600R
Event History
Mar 22, 2022
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for TOTOLINK N600R?
The vulnerability ID for TOTOLINK N600R is CVE-2022-26188.
2
What is the severity of CVE-2022-26188?
The severity of CVE-2022-26188 is critical with a severity value of 9.8.
3
How was the vulnerability discovered in TOTOLINK N600R?
The vulnerability was discovered via /setting/NTPSyncWithHost.
4
Which version of TOTOLINK N600R Firmware is affected by CVE-2022-26188?
TOTOLINK N600R V4.3.0cu.7570_B20200620 is affected by CVE-2022-26188.
5
Is TOTOLINK N600R vulnerable to CVE-2022-26188?
Yes, TOTOLINK N600R is vulnerable to CVE-2022-26188.
6
Is there a fix available for CVE-2022-26188?
Currently, there is no fix available for CVE-2022-26188. It is recommended to follow the vendor's instructions for mitigating the vulnerability.