First published: Wed Nov 23 2022(Updated: )
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink Lr350 Firmware | =9.3.5u.6369_b20220309 | |
TOTOLINK LR350 | ||
All of | ||
Totolink Lr350 Firmware | =9.3.5u.6369_b20220309 | |
TOTOLINK LR350 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this TOTOLINK NR1800X vulnerability is CVE-2022-44251.
The severity of CVE-2022-44251 is critical with a CVSS score of 9.8.
The TOTOLINK NR1800X vulnerability allows command injection via the ussd parameter in the setUssd function, which can be exploited by an attacker to execute arbitrary commands on the system.
TOTOLINK NR1800X V9.1.0u.6279_B20210910 is affected by the vulnerability.
To fix the TOTOLINK NR1800X vulnerability, it is recommended to update the firmware to a version that includes the security patches.