CVE-2022-41518: OS Command Injection
TOTOLINK NR1800X V9.1.0u.6279B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41518?
CVE-2022-41518 is a command injection vulnerability discovered in TOTOLINK NR1800X V9.1.0u.6279_B20210910 firmware.
How severe is CVE-2022-41518?
CVE-2022-41518 has a severity rating of 9.8 (critical).
How does CVE-2022-41518 affect TOTOLINK NR1800X firmware?
CVE-2022-41518 affects TOTOLINK NR1800X V9.1.0u.6279_B20210910 firmware as it allows for command injection via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
Is TOTOLINK NR1800X firmware version 9.1.0u.6279_b20210910 vulnerable to CVE-2022-41518?
Yes, TOTOLINK NR1800X firmware version 9.1.0u.6279_b20210910 is vulnerable to CVE-2022-41518.
How can I fix CVE-2022-41518 in TOTOLINK NR1800X firmware?
To fix CVE-2022-41518 in TOTOLINK NR1800X firmware, it is recommended to apply a security patch or update the firmware to a version that addresses the vulnerability.