Command Injection Vulnerability in TOTOLink A720R Routers
CVE-2022-36456
7.8HIGH
What is CVE-2022-36456?
A command injection vulnerability has been identified in the TOTOLink A720R router, specifically in version V4.1.5cu.532_B20210610. This vulnerability arises from improper handling of the username parameter in the /cstecgi.cgi script, allowing an attacker to execute arbitrary commands on the device. Exploiting this vulnerability could lead to unauthorized access and control over the affected router, posing significant risks for network security.