CVE-2022-36455: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLink A3600R V4.1.2cu.5182B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
Affected Software
2 affected components
TOTOLINK A3600r Firmware=4.1.2cu.5182_b20201102
TOTOLINK A3600R
Event History
Aug 25, 2022
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36455?
CVE-2022-36455 is a command injection vulnerability found in the TOTOLink A3600R V4.1.2cu.5182_B20201102 firmware.
2
How severe is CVE-2022-36455?
CVE-2022-36455 has a severity score of 7.8, indicating a high level of severity.
3
What is the affected software?
The affected software is Totolink A3600r Firmware version 4.1.2cu.5182_b20201102.
4
How can I fix CVE-2022-36455?
To fix CVE-2022-36455, it is recommended to update the TOTOLink A3600R firmware to a patched version provided by the manufacturer.
5
Is TOTOLink A3600R V4.1.2cu.5182_B20201102 vulnerable?
Yes, TOTOLink A3600R V4.1.2cu.5182_B20201102 is vulnerable to CVE-2022-36455.