CVE-2022-28909: OS Command Injection
Published May 10, 2022
·Updated
TOTOLink N600R V5.3c.7159B20190425 was discovered to contain a command injection vulnerability via the webwlanidx parameter in /setting/setWebWlanIdx.
Affected Software
2 affected components
TOTOLINK N600R firmware=5.3c.7159_b20190425
TOTOLINK N600R
Event History
May 10, 2022
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28909?
CVE-2022-28909 is a command injection vulnerability found in TOTOLink N600R V5.3c.7159_B20190425 firmware.
2
How severe is CVE-2022-28909?
CVE-2022-28909 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2022-28909 affect TOTOLink N600R firmware?
CVE-2022-28909 allows attackers to execute arbitrary commands through the webwlanidx parameter in /setting/setWebWlanIdx.
4
Is TOTOLink N600R firmware version 5.3c.7159_b20190425 vulnerable to CVE-2022-28909?
Yes, TOTOLink N600R firmware version 5.3c.7159_b20190425 is vulnerable to CVE-2022-28909.
5
How can I fix the CVE-2022-28909 vulnerability?
To fix the CVE-2022-28909 vulnerability, it is recommended to update TOTOLink N600R firmware to a patched version provided by the manufacturer.