CVE-2022-28579: OS Command Injection
Published May 5, 2022
·Updated
It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Affected Software
2 affected components
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
Event History
May 5, 2022
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28579?
CVE-2022-28579 is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router.
2
How does CVE-2022-28579 affect the TOTOlink A7100RU router?
CVE-2022-28579 allows an attacker to execute arbitrary commands on the TOTOlink A7100RU router through a carefully constructed payload.
3
What is the severity of CVE-2022-28579?
CVE-2022-28579 has a severity rating of 9.8 (critical).
4
What is the affected software version of CVE-2022-28579?
The affected software version of CVE-2022-28579 is Totolink A7100ru Firmware v7.4cu.2313_b20191024.
5
Is the TOTOlink A7100RU router vulnerable to CVE-2022-28579?
Yes, the TOTOlink A7100RU router is vulnerable to CVE-2022-28579.