CVE-2022-36459: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK A3700R V9.1.2u.6134B20201202 was discovered to contain a command injection vulnerability via the hosttime parameter in the function NTPSyncWithHost.
Affected Software
2 affected components
Totolink A3700R Firmware=9.1.2u.6134_b20201202
Totolink A3700R Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of the TOTOLINK A3700R vulnerability?
The vulnerability ID of the TOTOLINK A3700R vulnerability is CVE-2022-36459.
2
What is the severity of CVE-2022-36459?
The severity of CVE-2022-36459 is high with a CVSS score of 7.8.
3
How does the TOTOLINK A3700R vulnerability occur?
The TOTOLINK A3700R vulnerability occurs through a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.
4
What software version is affected by CVE-2022-36459?
The Totolink A3700r Firmware version 9.1.2u.6134_b20201202 is affected by CVE-2022-36459.
5
Is the TOTOLINK A3700R device vulnerable to CVE-2022-36459?
No, the TOTOLINK A3700R device is not vulnerable to CVE-2022-36459.