Command Injection Vulnerability in TOTOLINK A7000R Router
CVE-2022-37082
7.8HIGH
Summary
A command injection vulnerability has been identified in the TOTOLINK A7000R router firmware version V9.1.0u.6115_B20201022. This flaw allows attackers to exploit the 'host_time' parameter within the function responsible for syncing time with a remote host. By injecting malicious commands through this parameter, an unauthorized user may gain access to execute arbitrary code on the router, compromising its functionality and network security.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved