First published: Thu Sep 15 2022(Updated: )
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A720r Firmware | =4.1.5cu.374 | |
TOTOLINK A720R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38535 refers to a remote code execution (RCE) vulnerability in the TOTOLINK-720R v4.1.5cu.374 firmware version.
CVE-2022-38535 allows attackers to execute remote code on TOTOLINK-720R v4.1.5cu.374 devices using the setTracerouteCfg function.
CVE-2022-38535 has a severity score of 7.2, which is classified as high severity.
To fix CVE-2022-38535, users should update their TOTOLINK-720R firmware to a version that has addressed the vulnerability.
CWE-78 is a common weakness enumeration code that refers to the use of incorrect permission assignment for a resource.