CVE-2022-37083: OS Command Injection
Published Aug 25, 2022
·Updated
TOTOLINK A7000R V9.1.0u.6115B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisCfg.
Affected Software
2 affected components
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK A7000R
Event History
Aug 25, 2022
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-37083.
2
What is the affected software?
The affected software is Totolink A7000R Firmware version 9.1.0u.6115_b20201022.
3
What is the severity of CVE-2022-37083?
The severity of CVE-2022-37083 is high.
4
How can the command injection vulnerability be exploited?
The command injection vulnerability can be exploited through the 'ip' parameter in the setDiagnosisCfg function.
5
Is there a fix available for CVE-2022-37083?
Currently, there is no specific fix available for CVE-2022-37083. It is recommended to stay updated with the latest firmware releases provided by the vendor.