CVE-2022-41525: OS Command Injection
Published Oct 6, 2022
·Updated
TOTOLINK NR1800X V9.1.0u.6279B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.
Affected Software
4 affected components
TOTOLINK Nr1800x Firmware=9.1.0u.6279_b20210910
TOTOLINK NR1800X
All of the following
TOTOLINK Nr1800x Firmware=9.1.0u.6279_b20210910
TOTOLINK NR1800X
Event History
Oct 6, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-41525?
CVE-2022-41525 is a command injection vulnerability found in TOTOLINK NR1800X V9.1.0u.6279_B20210910 firmware.
2
What is the severity of CVE-2022-41525?
CVE-2022-41525 has a severity rating of 9.8 (critical).
3
How does CVE-2022-41525 affect TOTOLINK NR1800X?
CVE-2022-41525 affects TOTOLINK NR1800X V9.1.0u.6279_B20210910 firmware by allowing command injection via the OpModeCfg function at /cgi-bin/cstecgi.cgi.
4
Is TOTOLINK NR1800X vulnerable to CVE-2022-41525?
TOTOLINK NR1800X V9.1.0u.6279_B20210910 firmware is vulnerable to CVE-2022-41525.
5
How can I fix the CVE-2022-41525 vulnerability in TOTOLINK NR1800X?
To fix the CVE-2022-41525 vulnerability in TOTOLINK NR1800X, update the firmware to a version that is not affected by the vulnerability.