Command Injection Vulnerability in TOTOLINK Routers
CVE-2022-25131
9.8CRITICAL
What is CVE-2022-25131?
A command injection vulnerability exists in the recvSlaveCloudCheckStatus function of TOTOLINK Technology routers. This flaw allows an attacker to execute arbitrary commands on the affected devices by sending a specially crafted MQTT packet. This could lead to unauthorized access and manipulation of the router's functionality, posing significant security risks to users.