First published: Tue Mar 22 2022(Updated: )
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink N600r Firmware | =4.3.0cu.7570_b20200620 | |
TOTOLINK N600R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for TOTOLINK N600R V4.3.0cu.7570_B20200620 is CVE-2022-26189.
CVE-2022-26189 has a severity rating of 9.8 (Critical).
CVE-2022-26189 allows an attacker to execute arbitrary commands via the langType parameter in the login interface of TOTOLINK N600R V4.3.0cu.7570_B20200620.
No, TOTOLINK N600R V4.3.0cu.7570_B20200620 is not the only affected software. TOTOLINK N600R with other firmware versions may also be affected.
To fix the command injection vulnerability in TOTOLINK N600R V4.3.0cu.7570_B20200620, update to a secure firmware version provided by the manufacturer.