CVE-2022-36487: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK N350RT V9.3.5u.6139B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.
Affected Software
2 affected components
Totolink N350RT Firmware=9.3.5u.6139_b20201216
Totolink N350RT Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36487?
CVE-2022-36487 has been rated as a high severity vulnerability due to its command injection capabilities.
2
How do I fix CVE-2022-36487?
To fix CVE-2022-36487, you should update theTOTOLINK N350RT firmware to a version that has addressed this vulnerability.
3
What is the impact of CVE-2022-36487?
CVE-2022-36487 allows an attacker to execute arbitrary commands on the affected device, potentially compromising its security.
4
Which versions of firmware are affected by CVE-2022-36487?
CVE-2022-36487 specifically affects TOTOLINK N350RT firmware version 9.3.5u.6139_B20201216.
5
Is the TOTOLINK N350RT hardware itself vulnerable under CVE-2022-36487?
No, the hardware itself is not vulnerable; it is the specific firmware version that contains the command injection flaw.