Command Injection Vulnerability in Totolink Routers
CVE-2022-26211

9.8CRITICAL

Key Information:

Vendor
Totolink
Vendor
CVE Published:
15 March 2022

Summary

Several Totolink router models, including A830R and A3100R, are susceptible to a command injection vulnerability in the CloudACMunualUpdate function. This issue arises from improper handling of the deviceMac and deviceName parameters, allowing attackers to send specially crafted requests that execute arbitrary commands on the affected devices. Network administrators should take immediate steps to secure their routers by applying the latest firmware updates and reviewing their configuration for potential exploits.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.