CVE-2022-36481: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK N350RT V9.3.5u.6139B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.
Affected Software
2 affected components
Totolink N350RT Firmware=9.3.5u.6139_b20201216
Totolink N350RT Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36481?
CVE-2022-36481 is classified as a high severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2022-36481?
To fix CVE-2022-36481, update the TOTOLINK N350RT firmware to a version later than 9.3.5u.6139_B20201216 that addresses this vulnerability.
3
What type of vulnerability is CVE-2022-36481?
CVE-2022-36481 is a command injection vulnerability that can be exploited via the ip parameter in the setDiagnosisCfg function.
4
What devices are affected by CVE-2022-36481?
CVE-2022-36481 specifically affects the TOTOLINK N350RT running firmware version 9.3.5u.6139_B20201216.
5
Can CVE-2022-36481 be exploited remotely?
Yes, CVE-2022-36481 can be exploited remotely, allowing attackers to execute arbitrary commands on the device.