First published: Thu Mar 23 2023(Updated: )
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Cp900 Firmware | =6.3c.566_b20171026 | |
TOTOLINK CP900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28496 is a command injection vulnerability discovered in TOTOLink outdoor CPE CP900 V6.3c.566_B20171026.
CVE-2022-28496 has a severity rating of 9.8 (Critical).
CVE-2022-28496 allows attackers to execute arbitrary commands on TOTOLink CP900 devices via a crafted request.
Yes, TOTOLink CP900 version 6.3c.566_B20171026 is vulnerable to CVE-2022-28496.
To fix the CVE-2022-28496 vulnerability on TOTOLink CP900, it is recommended to update to a patched firmware version provided by the vendor.