First published: Thu May 05 2022(Updated: )
TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink N600r Firmware | =5.3c.5507_b20171031 | |
TOTOLINK N600R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27411 is a command injection vulnerability found in the TOTOLINK N600R v5.3c.5507_B20171031 firmware.
CVE-2022-27411 allows an attacker to execute arbitrary commands via the QUERY_STRING parameter in the 'Main' function of the TOTOLINK N600R firmware.
CVE-2022-27411 has a severity rating of 9.8 (Critical).
A patch or updated firmware released by TOTOLINK is required to fix the CVE-2022-27411 vulnerability in the N600R firmware.
More information about CVE-2022-27411 can be found on the GitHub page at https://github.com/ejdhssh/IOT_Vul.