First published: Thu Mar 23 2023(Updated: )
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Cp900 Firmware | =6.3c.566_b20171026 | |
TOTOLINK CP900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28494 is a command injection vulnerability discovered in TOTOLink outdoor CPE CP900 V6.3c.566_B20171026.
The severity of CVE-2022-28494 is critical with a CVSS score of 9.8.
CVE-2022-28494 allows attackers to execute arbitrary commands in TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 via the filename parameter in the setUpgradeFW function.
At the moment, there is no official patch or fix available for CVE-2022-28494. It is recommended to monitor vendor websites for any updates or security advisories.
The CWE for CVE-2022-28494 are CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).