CVE-2022-36456: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLink A720R V4.1.5cu.532B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.
Affected Software
2 affected components
TOTOLINK A720r Firmware=4.1.5cu.532_b20210610
TOTOLINK A720R
Event History
Aug 25, 2022
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36456?
CVE-2022-36456 is a command injection vulnerability in TOTOLink A720R V4.1.5cu.532_B20210610, specifically in the username parameter of /cstecgi.cgi.
2
How severe is CVE-2022-36456?
CVE-2022-36456 has a severity score of 7.8, which is classified as high.
3
What software is affected by CVE-2022-36456?
TOTOLink A720R V4.1.5cu.532_B20210610 firmware is affected by CVE-2022-36456.
4
How can I fix CVE-2022-36456?
To fix CVE-2022-36456, it is recommended to update the TOTOLink A720R firmware to a version that addresses the vulnerability.
5
What is the CWE classification for CVE-2022-36456?
CVE-2022-36456 is classified under CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).