CVE-2022-36485: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK N350RT V9.3.5u.6139B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
Affected Software
2 affected components
Totolink N350RT Firmware=9.3.5u.6139_b20201216
Totolink N350RT Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36485?
CVE-2022-36485 has a high severity rating due to the presence of a command injection vulnerability.
2
How do I fix CVE-2022-36485?
To fix CVE-2022-36485, update the TOTOLINK N350RT firmware to the latest version provided by the manufacturer.
3
What systems are affected by CVE-2022-36485?
CVE-2022-36485 affects the TOTOLINK N350RT with firmware version 9.3.5u.6139_B20201216.
4
What type of vulnerability is CVE-2022-36485?
CVE-2022-36485 is classified as a command injection vulnerability.
5
Can CVE-2022-36485 be exploited remotely?
Yes, CVE-2022-36485 can potentially be exploited remotely due to improper input validation in the vulnerable firmware.