First published: Thu Aug 25 2022(Updated: )
TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A720r Firmware | =4.1.5cu.532_b20210610 | |
TOTOLINK A720R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36456 is a command injection vulnerability in TOTOLink A720R V4.1.5cu.532_B20210610, specifically in the username parameter of /cstecgi.cgi.
CVE-2022-36456 has a severity score of 7.8, which is classified as high.
TOTOLink A720R V4.1.5cu.532_B20210610 firmware is affected by CVE-2022-36456.
To fix CVE-2022-36456, it is recommended to update the TOTOLink A720R firmware to a version that addresses the vulnerability.
CVE-2022-36456 is classified under CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).