Command Injection Vulnerability in TOTOLINK Technology Router
CVE-2022-25133
9.8CRITICAL
What is CVE-2022-25133?
A command injection vulnerability exists in the TOTOLINK Technology router T6 firmware. The issue, which arises in the function isAssocPriDevice, allows attackers to craft malicious MQTT packets, enabling them to execute arbitrary commands on the device. This can lead to unauthorized access and potential compromise of network security. Users of affected devices should apply available patches and adopt protective measures.