CVE-2022-28491: OS Command Injection
TOTOLink outdoor CPE CP900 V6.3c.566B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28491?
The severity of CVE-2022-28491 is critical with a CVSS score of 9.8.
What is the affected software version for CVE-2022-28491?
The affected software version for CVE-2022-28491 is Totolink outdoor CPE CP900 V6.3c.566_B20171026.
How does CVE-2022-28491 work?
CVE-2022-28491 is a command injection vulnerability in the NTPSyncWithHost function of Totolink outdoor CPE CP900 V6.3c.566_B20171026, where an attacker can execute arbitrary commands via a crafted request using the host_name parameter.
Are there any references for CVE-2022-28491?
Yes, there are references available for CVE-2022-28491. You can find them here: [link1](https://github.com/B2eFly/CVE/blob/main/totolink/CP900/2/2.md) and [link2](https://github.com/B2eFly/Router/blob/main/totolink/CP900/1/2.md).
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-28491?
The Common Weakness Enumeration (CWE) ID for CVE-2022-28491 is CWE-77 and CWE-78.