CVE-2022-26189: Command Injection
Published Mar 22, 2022
·Updated
TOTOLINK N600R V4.3.0cu.7570B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
Affected Software
2 affected components
TOTOLINK N600R firmware=4.3.0cu.7570_b20200620
TOTOLINK N600R
Event History
Mar 22, 2022
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for TOTOLINK N600R V4.3.0cu.7570_B20200620?
The vulnerability ID for TOTOLINK N600R V4.3.0cu.7570_B20200620 is CVE-2022-26189.
2
What is the severity rating of CVE-2022-26189?
CVE-2022-26189 has a severity rating of 9.8 (Critical).
3
How does CVE-2022-26189 impact TOTOLINK N600R V4.3.0cu.7570_B20200620?
CVE-2022-26189 allows an attacker to execute arbitrary commands via the langType parameter in the login interface of TOTOLINK N600R V4.3.0cu.7570_B20200620.
4
Is TOTOLINK N600R V4.3.0cu.7570_B20200620 the only affected software?
No, TOTOLINK N600R V4.3.0cu.7570_B20200620 is not the only affected software. TOTOLINK N600R with other firmware versions may also be affected.
5
How can I fix the command injection vulnerability in TOTOLINK N600R V4.3.0cu.7570_B20200620?
To fix the command injection vulnerability in TOTOLINK N600R V4.3.0cu.7570_B20200620, update to a secure firmware version provided by the manufacturer.