Command Injection Vulnerability in Totolink Routers
CVE-2022-26211
9.8CRITICAL
Summary
Several Totolink router models, including A830R and A3100R, are susceptible to a command injection vulnerability in the CloudACMunualUpdate function. This issue arises from improper handling of the deviceMac and deviceName parameters, allowing attackers to send specially crafted requests that execute arbitrary commands on the affected devices. Network administrators should take immediate steps to secure their routers by applying the latest firmware updates and reviewing their configuration for potential exploits.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved