CVE-2022-28497: Command Injection
TOTOLink outdoor CPE CP900 V6.3c.566B20171026 is discovered to contain a command injection vulnerability in the mtdwritebootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28497?
CVE-2022-28497 is a command injection vulnerability found in the TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 firmware.
How severe is CVE-2022-28497?
CVE-2022-28497 has a severity rating of 9.8, which is considered critical.
What software version is affected by CVE-2022-28497?
The TOTOLink outdoor CPE CP900 firmware version 6.3c.566_B20171026 is affected by CVE-2022-28497.
How can an attacker exploit CVE-2022-28497?
An attacker can exploit CVE-2022-28497 by sending a crafted request with a malicious filename parameter to the vulnerable device, allowing them to execute arbitrary commands.
Is TOTOLink CP900 vulnerable to CVE-2022-28497?
No, the TOTOLink CP900 hardware is not vulnerable to CVE-2022-28497.