CVE-2022-38535: OS Command Injection
Published Sep 15, 2022
·Updated
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.
Affected Software
2 affected components
TOTOLINK A720r Firmware=4.1.5cu.374
TOTOLINK A720R
Event History
Sep 15, 2022
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
Description
Frequently Asked Questions
1
What is CVE-2022-38535?
CVE-2022-38535 refers to a remote code execution (RCE) vulnerability in the TOTOLINK-720R v4.1.5cu.374 firmware version.
2
How does CVE-2022-38535 affect TOTOLINK-720R v4.1.5cu.374?
CVE-2022-38535 allows attackers to execute remote code on TOTOLINK-720R v4.1.5cu.374 devices using the setTracerouteCfg function.
3
What is the severity of CVE-2022-38535?
CVE-2022-38535 has a severity score of 7.2, which is classified as high severity.
4
How can I fix CVE-2022-38535?
To fix CVE-2022-38535, users should update their TOTOLINK-720R firmware to a version that has addressed the vulnerability.
5
What is CWE-78?
CWE-78 is a common weakness enumeration code that refers to the use of incorrect permission assignment for a resource.