CVE-2022-26213: OS Command Injection
Totolink X5000RFirmware v9.1.0u.6118B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26213?
CVE-2022-26213 is a command injection vulnerability discovered in Totolink X5000R_Firmware v9.1.0u.6118_B20201102.
How severe is CVE-2022-26213?
CVE-2022-26213 has a severity score of 9.8, which is considered critical.
How does CVE-2022-26213 affect Totolink X5000R_Firmware?
CVE-2022-26213 allows attackers to execute arbitrary commands in Totolink X5000R_Firmware v9.1.0u.6118_B20201102 via the tz parameters in the setNtpCfg function.
How can I fix CVE-2022-26213?
To fix CVE-2022-26213, it is recommended to update Totolink X5000R_Firmware to a patched version provided by the vendor.
Where can I find more information about CVE-2022-26213?
More information about CVE-2022-26213 can be found at the following reference: https://github.com/pjqwudi1/my_vuln/blob/main/totolink/vuln_21/21.md