First published: Thu Aug 25 2022(Updated: )
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK A7000R firmware | =9.1.0u.6115_b20201022 | |
TOTOLINK A7000R firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for TOTOLINK A7000R V9.1.0u.6115_B20201022 is CVE-2022-37076.
The severity of CVE-2022-37076 is rated as high, with a severity score of 7.8.
The command injection vulnerability in TOTOLINK A7000R V9.1.0u.6115_B20201022 occurs through the FileName parameter in the UploadFirmwareFile function.
Yes, TOTOLINK A7000R V9.1.0u.6115_B20201022 can be exploited remotely.
At the time of discovery, there was no known fix available for the TOTOLINK A7000R V9.1.0u.6115_B20201022 vulnerability.