CVE-2022-37843: Command Injection
Published Sep 6, 2022
·Updated
In TOTOLINK A860R V4.1.2cu.5182B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for execution without filtering, resulting in a command injection vulnerability.
Affected Software
2 affected components
TOTOLINK A860r Firmware=4.1.2cu.5182_b20201027
TOTOLINK A860R
Event History
Sep 6, 2022
CVE Published
via MITRE·04:34 PM
Data Sourced
via MITRE·04:34 PM
Description
Frequently Asked Questions
1
What is CVE-2022-37843?
CVE-2022-37843 is a command injection vulnerability in TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware.
2
What is the severity of CVE-2022-37843?
CVE-2022-37843 has a severity rating of 9.8 (Critical).
3
How does CVE-2022-37843 affect TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware?
CVE-2022-37843 allows attackers to execute arbitrary commands in TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware due to the lack of input filtering.
4
What is the affected software version of CVE-2022-37843?
CVE-2022-37843 affects TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware.
5
Is TOTOLINK A860R V4.1.2cu.5182_B20201027 vulnerable to CVE-2022-37843?
Yes, TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware is vulnerable to CVE-2022-37843.