CVE-2022-26209: OS Command Injection
Totolink A830R V5.9c.4729B20191112, A3100R V4.1.2cu.5050B20200504, A950RG V4.1.2cu.5161B20200903, A800R V4.1.2cu.5137B20200730, A3000RU V5.9c.5185B20201128, and A810R V4.1.2cu.5182B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26209?
CVE-2022-26209 is a command injection vulnerability in Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026.
What is the severity of CVE-2022-26209?
The severity of CVE-2022-26209 is critical, with a severity value of 9.8.
How does CVE-2022-26209 affect Totolink A830R?
CVE-2022-26209 affects Totolink A830R V5.9c.4729_B20191112 firmware.
How does CVE-2022-26209 affect Totolink A3100R?
CVE-2022-26209 affects Totolink A3100R V4.1.2cu.5050_B20200504 firmware.
Is Totolink A950RG affected by CVE-2022-26209?
Yes, Totolink A950RG V4.1.2cu.5161_B20200903 firmware is affected by CVE-2022-26209.