First published: Thu Oct 06 2022(Updated: )
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Nr1800x Firmware | =9.1.0u.6279_b20210910 | |
TOTOLINK NR1800X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41518 is a command injection vulnerability discovered in TOTOLINK NR1800X V9.1.0u.6279_B20210910 firmware.
CVE-2022-41518 has a severity rating of 9.8 (critical).
CVE-2022-41518 affects TOTOLINK NR1800X V9.1.0u.6279_B20210910 firmware as it allows for command injection via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
Yes, TOTOLINK NR1800X firmware version 9.1.0u.6279_b20210910 is vulnerable to CVE-2022-41518.
To fix CVE-2022-41518 in TOTOLINK NR1800X firmware, it is recommended to apply a security patch or update the firmware to a version that addresses the vulnerability.