First published: Tue Sep 06 2022(Updated: )
In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for execution without filtering, resulting in a command injection vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A860r Firmware | =4.1.2cu.5182_b20201027 | |
TOTOLink A860R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37843 is a command injection vulnerability in TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware.
CVE-2022-37843 has a severity rating of 9.8 (Critical).
CVE-2022-37843 allows attackers to execute arbitrary commands in TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware due to the lack of input filtering.
CVE-2022-37843 affects TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware.
Yes, TOTOLINK A860R V4.1.2cu.5182_B20201027 firmware is vulnerable to CVE-2022-37843.