Record summary

CVE-2022-25082 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 1, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALTOTOLink - Unauthenticated Command InjectionCVSS 9.8

TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the Main function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire network.

Remediation

Apply the latest firmware update provided by the vendor to fix the command injection vulnerability.

WeaknessesCWE-78
Authorsgy741
Template tagscvecve2022totolinkrouterunauthrceiotintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5204_b20210112:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2