Command Injection Vulnerability in TOTOLink A720R Routers
CVE-2022-36456
7.8HIGH
Summary
A command injection vulnerability has been identified in the TOTOLink A720R router, specifically in version V4.1.5cu.532_B20210610. This vulnerability arises from improper handling of the username parameter in the /cstecgi.cgi script, allowing an attacker to execute arbitrary commands on the device. Exploiting this vulnerability could lead to unauthorized access and control over the affected router, posing significant risks for network security.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved