CVE-2022-44252: OS Command Injection
Published Nov 23, 2022
·Updated
TOTOLINK NR1800X V9.1.0u.6279B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
Affected Software
4 affected components
TOTOLINK Lr350 Firmware=9.3.5u.6369_b20220309
TOTOLINK LR350
All of the following
TOTOLINK Lr350 Firmware=9.3.5u.6369_b20220309
TOTOLINK LR350
Event History
Nov 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this command injection vulnerability?
The vulnerability ID is CVE-2022-44252.
2
What is the severity of CVE-2022-44252?
CVE-2022-44252 has a severity rating of 9.8 (Critical).
3
What is the affected software of CVE-2022-44252?
The affected software is TOTOLINK NR1800X V9.1.0u.6279_B20210910.
4
How does CVE-2022-44252 work?
CVE-2022-44252 allows command injection through the FileName parameter in the setUploadSetting function.
5
Are there any known fixes for CVE-2022-44252?
Currently, there are no known fixes for CVE-2022-44252. It is recommended to follow the provided reference for any updates or patches.