CVE-2022-36460: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK A3700R V9.1.2u.6134B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
Affected Software
2 affected components
Totolink A3700R Firmware=9.1.2u.6134_b20201202
Totolink A3700R Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for TOTOLINK A3700R?
The vulnerability ID for TOTOLINK A3700R is CVE-2022-36460.
2
What is the severity of CVE-2022-36460?
The severity of CVE-2022-36460 is high with a CVSS score of 7.8.
3
How can the TOTOLINK A3700R be affected by this vulnerability?
TOTOLINK A3700R V9.1.2u.6134_B20201202 is affected by a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
4
How can I fix CVE-2022-36460 in TOTOLINK A3700R?
Currently, there is no known fix or patch for CVE-2022-36460. It is recommended to follow the vendor's security advisories for updates.
5
Where can I find more information about CVE-2022-36460?
You can find more information about CVE-2022-36460 at the following link: [CVE-2022-36460](https://github.com/Darry-lang1/vuln/blob/main/TOTOLINK/A3700R/4/readme.md).