CVE-2022-28495: OS Command Injection
TOTOLink outdoor CPE CP900 V6.3c.566B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28495?
CVE-2022-28495 is a command injection vulnerability found in TOTOLink outdoor CPE CP900 V6.3c.566_B20171026.
How severe is CVE-2022-28495?
CVE-2022-28495 has a severity rating of 9.8 (critical).
What software is affected by CVE-2022-28495?
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is affected by CVE-2022-28495.
How can an attacker exploit CVE-2022-28495?
An attacker can exploit CVE-2022-28495 by sending a crafted request containing arbitrary commands to the setWebWlanIdx function via the webWlanIdx parameter.
Are there any references available for CVE-2022-28495?
Yes, you can find references for CVE-2022-28495 at the following links: [link1](https://github.com/B2eFly/CVE/blob/main/totolink/CP900/3/3.md) and [link2](https://github.com/B2eFly/Router/blob/main/totolink/CP900/3/3.md).