CVE-2022-48125: OS Command Injection
Published Jan 20, 2023
·Updated
TOTOlink A7100RU V7.4cu.2313B20191024 was discovered to contain a command injection vulnerability via the password parameter in the setting/setOpenVpnCertGenerationCfg function.
Affected Software
4 affected components
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
All of the following
TOTOLINK A7100ru Firmware=7.4cu.2313_b20191024
TOTOLINK A7100RU
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-48125?
CVE-2022-48125 is a command injection vulnerability discovered in TOTOlink A7100RU V7.4cu.2313_B20191024.
2
How severe is CVE-2022-48125?
CVE-2022-48125 has a severity score of 9.8, which is categorized as critical.
3
How does CVE-2022-48125 impact TOTOlink A7100RU V7.4cu.2313_B20191024?
CVE-2022-48125 allows attackers to execute arbitrary commands via the password parameter in the setting/setOpenVpnCertGenerationCfg function.
4
Is TOTOlink A7100RU V7.4cu.2313_B20191024 affected by CVE-2022-48125?
Yes, TOTOlink A7100RU V7.4cu.2313_B20191024 is affected by CVE-2022-48125.
5
Is there a fix for CVE-2022-48125?
At the moment, there is no known fix or patch for CVE-2022-48125. It is recommended to follow any security advisories from the vendor.