CVE-2022-40475: OS Command Injection
Published Sep 29, 2022
·Updated
TOTOLINK A860R V4.1.2cu.5182B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.
Affected Software
4 affected components
TOTOLINK A860r Firmware=4.1.2cu.5182_b20201027
TOTOLINK A860R
All of the following
TOTOLINK A860r Firmware=4.1.2cu.5182_b20201027
TOTOLINK A860R
Event History
Sep 29, 2022
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40475?
CVE-2022-40475 is classified as a high-severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2022-40475?
To fix CVE-2022-40475, it is recommended to update the TOTOLINK A860R firmware to a version that addresses this vulnerability.
3
What components are affected by CVE-2022-40475?
The component affected by CVE-2022-40475 is /cgi-bin/downloadFile.cgi in the TOTOLINK A860R firmware version 4.1.2cu.5182_B20201027.
4
Is CVE-2022-40475 exploitable remotely?
Yes, CVE-2022-40475 is exploitable remotely, allowing attackers to execute commands on the device from anywhere.
5
What platforms are impacted by CVE-2022-40475?
CVE-2022-40475 impacts the TOTOLINK A860R running the specific firmware version 4.1.2cu.5182_B20201027.