CVE-2022-36458: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK A3700R V9.1.2u.6134B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.
Affected Software
2 affected components
Totolink A3700R Firmware=9.1.2u.6134_b20201202
Totolink A3700R Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36458?
CVE-2022-36458 is a command injection vulnerability found in TOTOLINK A3700R V9.1.2u.6134_B20201202.
2
How severe is CVE-2022-36458?
CVE-2022-36458 has a severity score of 7.8, which is considered high.
3
Which software versions are affected by CVE-2022-36458?
TOTOLINK A3700R V9.1.2u.6134_B20201202 is affected by CVE-2022-36458.
4
How can I fix CVE-2022-36458?
Update your TOTOLINK A3700R firmware to a version that is not vulnerable to CVE-2022-36458.
5
Where can I find more information about CVE-2022-36458?
You can find more information about CVE-2022-36458 at the following link: [https://github.com/Darry-lang1/vuln/blob/main/TOTOLINK/A3700R/2/readme.md](https://github.com/Darry-lang1/vuln/blob/main/TOTOLINK/A3700R/2/readme.md)