CVE-2022-28583: OS Command Injection
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28583?
CVE-2022-28583 refers to a command injection vulnerability in the setWiFiWpsCfg interface in the TOTOlink A7100RU (v7.4cu.2313_b20191024) router.
How severe is CVE-2022-28583?
CVE-2022-28583 has a severity rating of 9.8 (critical).
How does CVE-2022-28583 affect the Totolink A7100ru Firmware?
CVE-2022-28583 allows an attacker to execute arbitrary commands through a carefully constructed payload in the setWiFiWpsCfg interface of the Totolink A7100ru Firmware (v7.4cu.2313_b20191024).
Is TOTOlink A7100RU vulnerable to CVE-2022-28583?
No, TOTOlink A7100RU is not vulnerable to CVE-2022-28583.
How can I fix CVE-2022-28583?
To fix CVE-2022-28583, it is recommended to update the Totolink A7100ru Firmware to a version that patches the vulnerability.