CVE-2022-37860: OS Command Injection
Published Sep 12, 2022
·Updated
The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.
Affected Software
2 affected components
TP-Link M7350 Firmware=190531
TP-Link M7350=v3
Remediation
Event History
Sep 12, 2022
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-37860?
CVE-2022-37860 is considered a high severity vulnerability due to its potential for pre-authentication command injection.
2
How do I fix CVE-2022-37860?
To fix CVE-2022-37860, update the firmware of the TP-Link M7350 to a version higher than 190531.
3
What devices are affected by CVE-2022-37860?
CVE-2022-37860 affects the TP-Link M7350 V3 specifically with firmware version 190531.
4
What is the nature of the vulnerability in CVE-2022-37860?
The nature of the vulnerability in CVE-2022-37860 involves a command injection that occurs before authentication.
5
Can CVE-2022-37860 lead to unauthorized access?
Yes, CVE-2022-37860 can potentially allow attackers to execute commands without authentication, leading to unauthorized access.