CVE-2022-28582: OS Command Injection
Published May 5, 2022
·Updated
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Affected Software
2 affected components
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
Event History
May 5, 2022
CVE Published
via MITRE·05:44 PM
Data Sourced
via MITRE·05:44 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-28582.
2
What is the severity of the vulnerability?
The severity of the vulnerability is critical with a score of 9.8.
3
What is the affected software?
The affected software is TOTOlink A7100RU (v7.4cu.2313_b20191024) router firmware version 7.4cu.2313_b20191024.
4
How does the vulnerability occur?
The vulnerability occurs in the setWiFiSignalCfg interface, allowing an attacker to execute arbitrary commands through a carefully constructed payload.
5
How can I fix CVE-2022-28582?
To fix CVE-2022-28582, it is recommended to update the TOTOlink A7100RU router firmware to a patched version.