CVE-2022-48126: OS Command Injection
TOTOlink A7100RU V7.4cu.2313B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenVpnCertGenerationCfg function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-48126?
CVE-2022-48126 is a command injection vulnerability found in TOTOlink A7100RU V7.4cu.2313_B20191024.
How severe is CVE-2022-48126?
CVE-2022-48126 has a severity score of 9.8, which is considered critical.
What is the affected software for CVE-2022-48126?
The affected software for CVE-2022-48126 is TOTOlink A7100RU V7.4cu.2313_B20191024 firmware.
How can the command injection vulnerability be exploited in CVE-2022-48126?
The command injection vulnerability in CVE-2022-48126 can be exploited through the username parameter in the setting/setOpenVpnCertGenerationCfg function.
Is there a fix available for CVE-2022-48126?
Currently, there is no known fix for CVE-2022-48126. It is recommended to update to a patched version when available or consider implementing mitigations.