CVE-2022-37076: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK A7000R V9.1.0u.6115B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
Affected Software
2 affected components
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK A7000R
Event History
Aug 25, 2022
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for TOTOLINK A7000R V9.1.0u.6115_B20201022?
The vulnerability ID for TOTOLINK A7000R V9.1.0u.6115_B20201022 is CVE-2022-37076.
2
What is the severity of CVE-2022-37076?
The severity of CVE-2022-37076 is rated as high, with a severity score of 7.8.
3
How does the command injection vulnerability in TOTOLINK A7000R V9.1.0u.6115_B20201022 work?
The command injection vulnerability in TOTOLINK A7000R V9.1.0u.6115_B20201022 occurs through the FileName parameter in the UploadFirmwareFile function.
4
Can TOTOLINK A7000R V9.1.0u.6115_B20201022 be exploited remotely?
Yes, TOTOLINK A7000R V9.1.0u.6115_B20201022 can be exploited remotely.
5
Is there a fix available for the TOTOLINK A7000R V9.1.0u.6115_B20201022 vulnerability?
At the time of discovery, there was no known fix available for the TOTOLINK A7000R V9.1.0u.6115_B20201022 vulnerability.