CVE-2022-28494: OS Command Injection
TOTOLink outdoor CPE CP900 V6.3c.566B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28494?
CVE-2022-28494 is a command injection vulnerability discovered in TOTOLink outdoor CPE CP900 V6.3c.566_B20171026.
What is the severity of CVE-2022-28494?
The severity of CVE-2022-28494 is critical with a CVSS score of 9.8.
How does CVE-2022-28494 affect TOTOLink outdoor CPE CP900 V6.3c.566_B20171026?
CVE-2022-28494 allows attackers to execute arbitrary commands in TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 via the filename parameter in the setUpgradeFW function.
How can I fix CVE-2022-28494 in TOTOLink outdoor CPE CP900 V6.3c.566_B20171026?
At the moment, there is no official patch or fix available for CVE-2022-28494. It is recommended to monitor vendor websites for any updates or security advisories.
What is the Common Weakness Enumeration (CWE) for CVE-2022-28494?
The CWE for CVE-2022-28494 are CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).