CVE-2022-38534: OS Command Injection
Published Sep 15, 2022
·Updated
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function.
Affected Software
2 affected components
TOTOLINK A720r Firmware=4.1.5cu.374
TOTOLINK A720R
Event History
Sep 15, 2022
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
Description
Frequently Asked Questions
1
What is CVE-2022-38534?
CVE-2022-38534 is a remote code execution (RCE) vulnerability found in TOTOLINK-720R v4.1.5cu.374.
2
How severe is CVE-2022-38534?
CVE-2022-38534 has a severity score of 7.2, which is considered high.
3
What software is affected by CVE-2022-38534?
TOTOLINK-720R v4.1.5cu.374 is affected by CVE-2022-38534.
4
How can I fix CVE-2022-38534?
Currently, there is no known fix or patch for CVE-2022-38534. It is recommended to follow any security advisories provided by the vendor.
5
What is the Common Weakness Enumeration (CWE) for CVE-2022-38534?
The CWE for CVE-2022-38534 is CWE-78, which is for Improper Neutralization of Special Elements used in an OS Command (OS Command Injection).