CVE-2022-28496: Command Injection
TOTOLink outdoor CPE CP900 V6.3c.566B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28496?
CVE-2022-28496 is a command injection vulnerability discovered in TOTOLink outdoor CPE CP900 V6.3c.566_B20171026.
What is the severity of CVE-2022-28496?
CVE-2022-28496 has a severity rating of 9.8 (Critical).
How does CVE-2022-28496 affect TOTOLink CP900?
CVE-2022-28496 allows attackers to execute arbitrary commands on TOTOLink CP900 devices via a crafted request.
Is TOTOLink CP900 version 6.3c.566_B20171026 vulnerable to CVE-2022-28496?
Yes, TOTOLink CP900 version 6.3c.566_B20171026 is vulnerable to CVE-2022-28496.
How can I fix the CVE-2022-28496 vulnerability on TOTOLink CP900?
To fix the CVE-2022-28496 vulnerability on TOTOLink CP900, it is recommended to update to a patched firmware version provided by the vendor.