Command Injection Vulnerability in TOTOLINK Routers
CVE-2022-25130

9.8CRITICAL

Key Information:

Vendor
Totolink
Vendor
CVE Published:
19 February 2022

Summary

TOTOLINK Technology routers, specifically the T6 and T10 models, are susceptible to a command injection vulnerability in the updateWifiInfo function. This security flaw enables attackers to execute arbitrary commands by sending a specially crafted MQTT packet to the affected devices, potentially compromising the integrity and confidentiality of the routers' operation. Users of the affected firmware versions are strongly advised to apply appropriate patches and monitor their networks for unusual activity.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.