CVE-2022-36486: OS Command Injection
TOTOLINK N350RT V9.3.5u.6139B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36486?
CVE-2022-36486 is classified as a high severity vulnerability due to its command injection nature affecting firmware uploads.
How do I fix CVE-2022-36486?
To fix CVE-2022-36486, update the TOTOLINK N350RT firmware to the latest version released after V9.3.5u.6139_B20201216.
What does CVE-2022-36486 affect?
CVE-2022-36486 affects the TOTOLINK N350RT router running firmware version 9.3.5u.6139_B20201216.
What type of vulnerability is CVE-2022-36486?
CVE-2022-36486 is a command injection vulnerability that can be exploited through the FileName parameter during firmware upload.
Can CVE-2022-36486 be exploited remotely?
Yes, CVE-2022-36486 can be exploited remotely, allowing an attacker to execute arbitrary commands on the affected device.