CVE-2022-48124: OS Command Injection
Published Jan 20, 2023
·Updated
TOTOlink A7100RU V7.4cu.2313B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the setting/setOpenVpnCertGenerationCfg function.
Affected Software
4 affected components
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
All of the following
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the TOTOlink A7100RU firmware command injection vulnerability?
The vulnerability ID for the TOTOlink A7100RU firmware command injection vulnerability is CVE-2022-48124.
2
What is the severity of CVE-2022-48124?
CVE-2022-48124 has a severity rating of 9.8, which is considered critical.
3
What software version is affected by CVE-2022-48124?
The TOTOlink A7100RU firmware version 7.4cu.2313_B20191024 is affected by CVE-2022-48124.
4
How can the TOTOlink A7100RU firmware command injection vulnerability be exploited?
The TOTOlink A7100RU firmware command injection vulnerability can be exploited through the FileName parameter in the setting/setOpenVpnCertGenerationCfg function.
5
Is TOTOlink A7100RU vulnerable to CVE-2022-48124?
No, TOTOlink A7100RU is not vulnerable to CVE-2022-48124.