CVE-2022-29639: Command Injection
TOTOLINK A3100R V4.1.2cu.5050B20200504 and V4.1.2cu.5247B20211129 were discovered to contain a command injection vulnerability via the magicid parameter in the function ucicloudupdateconfig.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29639?
CVE-2022-29639 refers to a command injection vulnerability found in TOTOLINK A3100R firmware versions 4.1.2cu.5050_B20200504 and 4.1.2cu.5247_B20211129.
How severe is CVE-2022-29639?
CVE-2022-29639 has a severity rating of 8.1, which is classified as critical.
How does CVE-2022-29639 affect TOTOLINK A3100R?
CVE-2022-29639 allows an attacker to inject malicious commands via the 'magicid' parameter in the uci_cloudupdate_config function of TOTOLINK A3100R firmware versions 4.1.2cu.5050_B20200504 and 4.1.2cu.5247_B20211129.
Is TOTOLINK A3100R firmware version 4.1.2cu.5050_B20200504 vulnerable?
Yes, TOTOLINK A3100R firmware version 4.1.2cu.5050_B20200504 is vulnerable to the command injection vulnerability (CVE-2022-29639).
Is there a fix for CVE-2022-29639?
Currently, there is no official fix available for CVE-2022-29639. It is recommended to update to a patched version as soon as it is released by the vendor.