CVE-2022-46634: OS Command Injection
Published Dec 15, 2022
·Updated
TOTOlink A7100RU V7.4cu.2313B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.
Affected Software
4 affected components
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
All of the following
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
Event History
Dec 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-46634?
CVE-2022-46634 is a command injection vulnerability in TOTOlink A7100RU V7.4cu.2313_B20191024.
2
How severe is CVE-2022-46634?
CVE-2022-46634 is classified as critical with a severity score of 9.8.
3
What software is affected by CVE-2022-46634?
TOTOlink A7100RU V7.4cu.2313_B20191024 firmware is affected by CVE-2022-46634.
4
What is the CWE of CVE-2022-46634?
CVE-2022-46634 has common weakness enumeration (CWE) IDs 77 and 78.
5
Where can I find more information about CVE-2022-46634?
You can find more information about CVE-2022-46634 at the following link: [https://github.com/EPhaha/IOT_vuln/tree/main/TOTOLink/A7100RU/7](https://github.com/EPhaha/IOT_vuln/tree/main/TOTOLink/A7100RU/7)