CVE-2022-47853: OS Command Injection
Published Jan 17, 2023
·Updated
TOTOlink A7100RU V7.4cu.2313B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload.
Affected Software
4 affected components
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
All of the following
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
Event History
Jan 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47853?
The severity of CVE-2022-47853 is critical with a CVSS score of 9.8.
2
How does the Command Injection vulnerability in TOTOlink A7100RU V7.4cu.2313_B20191024 work?
The Command Injection vulnerability in TOTOlink A7100RU V7.4cu.2313_B20191024 allows an attacker to execute arbitrary commands through the httpd service.
3
What can an attacker do with the Command Injection vulnerability in TOTOlink A7100RU V7.4cu.2313_B20191024?
An attacker can obtain a stable root shell through a specially constructed payload.
4
Is TOTOlink A7100RU V7.4cu.2313_B20191024 the only affected software?
No, Totolink A7100ru Firmware version 7.4cu.2313_b20191024 is also affected.
5
Are there any known references or resources related to CVE-2022-47853?
Yes, you can find more information about this vulnerability at the following link: https://github.com/Am1ngl/ttt/tree/main/16