CVE-2022-36482: Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK N350RT V9.3.5u.6139B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function setLanguageCfg.
Affected Software
2 affected components
Totolink N350RT Firmware=9.3.5u.6139_b20201216
Totolink N350RT Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36482?
CVE-2022-36482 is classified as a high severity command injection vulnerability.
2
How do I fix CVE-2022-36482?
The recommended fix for CVE-2022-36482 is to upgrade the TOTOLINK N350RT firmware to a version later than 9.3.5u.6139_B20201216.
3
What systems are affected by CVE-2022-36482?
CVE-2022-36482 specifically affects the TOTOLINK N350RT firmware version 9.3.5u.6139_B20201216.
4
What kind of attack can be executed due to CVE-2022-36482?
CVE-2022-36482 allows attackers to execute arbitrary commands on the device due to improper input validation.
5
Is my device safe if I use a firmware version older than 9.3.5u.6139_B20201216?
No, using a firmware version older than 9.3.5u.6139_B20201216 leaves your device vulnerable to exploitation through CVE-2022-36482.