First published: Thu Sep 29 2022(Updated: )
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink A860r Firmware | =4.1.2cu.5182_b20201027 | |
TOTOLink A860R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40475 is classified as a high-severity vulnerability due to the potential for command injection.
To fix CVE-2022-40475, it is recommended to update the TOTOLINK A860R firmware to a version that addresses this vulnerability.
The component affected by CVE-2022-40475 is /cgi-bin/downloadFile.cgi in the TOTOLINK A860R firmware version 4.1.2cu.5182_B20201027.
Yes, CVE-2022-40475 is exploitable remotely, allowing attackers to execute commands on the device from anywhere.
CVE-2022-40475 impacts the TOTOLINK A860R running the specific firmware version 4.1.2cu.5182_B20201027.