CVE-2022-27411: Command Injection
Published May 5, 2022
·Updated
TOTOLINK N600R v5.3c.5507B20171031 was discovered to contain a command injection vulnerability via the QUERYSTRING parameter in the "Main" function.
Affected Software
2 affected components
TOTOLINK N600R firmware=5.3c.5507_b20171031
TOTOLINK N600R
Event History
May 5, 2022
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27411?
CVE-2022-27411 is a command injection vulnerability found in the TOTOLINK N600R v5.3c.5507_B20171031 firmware.
2
How does CVE-2022-27411 affect TOTOLINK N600R?
CVE-2022-27411 allows an attacker to execute arbitrary commands via the QUERY_STRING parameter in the 'Main' function of the TOTOLINK N600R firmware.
3
What is the severity of CVE-2022-27411?
CVE-2022-27411 has a severity rating of 9.8 (Critical).
4
How can I fix CVE-2022-27411?
A patch or updated firmware released by TOTOLINK is required to fix the CVE-2022-27411 vulnerability in the N600R firmware.
5
Where can I find more information about CVE-2022-27411?
More information about CVE-2022-27411 can be found on the GitHub page at https://github.com/ejdhssh/IOT_Vul.