CVE-2022-26214: OS Command Injection
Totolink A830R V5.9c.4729B20191112, A3100R V4.1.2cu.5050B20200504, A950RG V4.1.2cu.5161B20200903, A800R V4.1.2cu.5137B20200730, A3000RU V5.9c.5185B20201128, and A810R V4.1.2cu.5182B20201026 were discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the hosttime parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26214?
The severity of CVE-2022-26214 is critical, with a severity value of 9.8.
Which Totolink products are affected by CVE-2022-26214?
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 are affected by CVE-2022-26214.
What is the vulnerability description of CVE-2022-26214?
CVE-2022-26214 is a command injection vulnerability in the NTPSyncWithHost function of Totolink A830R, A3100R, A950RG, A800R, A3000RU, and A810R firmware.
How severe is the vulnerability in Totolink A830R firmware version 5.9c.4729_b20191112?
The vulnerability in Totolink A830R firmware version 5.9c.4729_b20191112 is critical with a severity value of 9.8.
Where can I find more information about CVE-2022-26214?
You can find more information about CVE-2022-26214 at the following reference link: [link](https://github.com/pjqwudi1/my_vuln/blob/main/totolink/vuln_29/29.md)