Command Injection Vulnerability in TOTOLINK Router A7000R
CVE-2022-37081
7.8HIGH
Summary
The TOTOLINK A7000R router is affected by a command injection vulnerability located in the 'command' parameter at 'setting/setTracerouteCfg'. This flaw allows an attacker to inject arbitrary commands that the router will execute, potentially compromising the device's integrity and allowing unauthorized access or control.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved