First published: Thu Mar 23 2023(Updated: )
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Cp900 Firmware | =6.3c.566_b20171026 | |
TOTOLINK CP900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28497 is a command injection vulnerability found in the TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 firmware.
CVE-2022-28497 has a severity rating of 9.8, which is considered critical.
The TOTOLink outdoor CPE CP900 firmware version 6.3c.566_B20171026 is affected by CVE-2022-28497.
An attacker can exploit CVE-2022-28497 by sending a crafted request with a malicious filename parameter to the vulnerable device, allowing them to execute arbitrary commands.
No, the TOTOLink CP900 hardware is not vulnerable to CVE-2022-28497.