CVE-2022-28911: OS Command Injection
Published May 10, 2022
·Updated
TOTOLink N600R V5.3c.7159B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/CloudACMunualUpdate.
Affected Software
2 affected components
TOTOLINK N600R firmware=5.3c.7159_b20190425
TOTOLINK N600R
Event History
May 10, 2022
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28911?
CVE-2022-28911 is a command injection vulnerability in TOTOLink N600R V5.3c.7159_B20190425 firmware.
2
How severe is CVE-2022-28911?
CVE-2022-28911 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2022-28911 affect TOTOLink N600R V5.3c.7159_B20190425 firmware?
CVE-2022-28911 affects TOTOLink N600R V5.3c.7159_B20190425 firmware by allowing command injection through the filename parameter in /setting/CloudACMunualUpdate.
4
Is TOTOLink N600R V5.3c.7159_B20190425 vulnerable to CVE-2022-28911?
Yes, TOTOLink N600R V5.3c.7159_B20190425 firmware is vulnerable to CVE-2022-28911.
5
How can I fix the CVE-2022-28911 vulnerability in TOTOLink N600R V5.3c.7159_B20190425 firmware?
To fix the CVE-2022-28911 vulnerability in TOTOLink N600R V5.3c.7159_B20190425 firmware, it is recommended to update to a patched version provided by the vendor.