CVE-2022-25082
totolink a950rg_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2022-25082 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 1, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
a950rg_firmwareBrowse totolink / a950rg_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALTOTOLink - Unauthenticated Command InjectionCVSS 9.8
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the Main function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire network.
Remediation
Apply the latest firmware update provided by the vendor to fix the command injection vulnerability.
Source: ProjectDiscovery