CVE-2022-36479: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK N350RT V9.3.5u.6139B20201216 was discovered to contain a command injection vulnerability via the hosttime parameter in the function NTPSyncWithHost.
Affected Software
2 affected components
Totolink N350RT Firmware=9.3.5u.6139_b20201216
Totolink N350RT Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36479?
CVE-2022-36479 is a command injection vulnerability discovered in TOTOLINK N350RT V9.3.5u.6139_B20201216 firmware.
2
What is the severity of CVE-2022-36479?
The severity of CVE-2022-36479 is high with a CVSS score of 7.8.
3
How does CVE-2022-36479 affect TOTOLINK N350RT?
CVE-2022-36479 affects TOTOLINK N350RT V9.3.5u.6139_B20201216 firmware.
4
Is TOTOLINK N350RT V9.3.5u.6139_B20201216 vulnerable?
Yes, TOTOLINK N350RT V9.3.5u.6139_B20201216 is vulnerable to CVE-2022-36479.
5
How can I fix CVE-2022-36479?
To fix CVE-2022-36479, it is recommended to update TOTOLINK N350RT firmware to a version that includes a patch for this vulnerability.