Command Injection Vulnerability in TOTOLINK NR1800X Router
CVE-2022-41525 
9.8CRITICAL
What is CVE-2022-41525?
A command injection vulnerability exists in the TOTOLINK NR1800X router that enables attackers to execute arbitrary commands through the OpModeCfg function located at /cgi-bin/cstecgi.cgi. This flaw can compromise the security of the device and potentially lead to unauthorized access or control over the network.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
 High
Availability:
 High
Attack Vector:
Network
Attack Complexity:
 Low
Privileges Required:
 None
User Interaction:
 None
Scope:
 Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
