CVE-2022-36461: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK A3700R V9.1.2u.6134B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
Affected Software
2 affected components
Totolink A3700R Firmware=9.1.2u.6134_b20201202
Totolink A3700R Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for TOTOLINK A3700R?
The vulnerability ID for TOTOLINK A3700R is CVE-2022-36461.
2
What is the severity of CVE-2022-36461?
The severity of CVE-2022-36461 is high with a CVSS score of 7.8.
3
How does the command injection vulnerability in TOTOLINK A3700R occur?
The command injection vulnerability in TOTOLINK A3700R occurs via the hostName parameter in the setOpModeCfg function.
4
Which software version of TOTOLINK A3700R is affected?
The TOTOLINK A3700R firmware version 9.1.2u.6134_b20201202 is affected.
5
Is all TOTOLINK A3700R hardware vulnerable to CVE-2022-36461?
No, only TOTOLINK A3700R devices with firmware version 9.1.2u.6134_b20201202 are vulnerable to CVE-2022-36461.