CVE-2022-37081: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK A7000R V9.1.0u.6115B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.
Affected Software
2 affected components
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK A7000R
Event History
Aug 25, 2022
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of TOTOLINK A7000R V9.1.0u.6115_B20201022?
The vulnerability ID is CVE-2022-37081.
2
What is the severity of CVE-2022-37081?
The severity of CVE-2022-37081 is high (7.8).
3
How does the vulnerability in TOTOLINK A7000R V9.1.0u.6115_B20201022 occur?
The vulnerability occurs due to a command injection vulnerability via the command parameter at setting/setTracerouteCfg.
4
Is TOTOLINK A7000R V9.1.0u.6115_B20201022 affected by the vulnerability?
Yes, TOTOLINK A7000R V9.1.0u.6115_B20201022 is affected by the vulnerability.
5
How can I fix the vulnerability in TOTOLINK A7000R V9.1.0u.6115_B20201022?
To fix the vulnerability, apply the latest firmware version provided by Totolink.