PT-2022-19743 · Totolink · Totolink A3100R

Hijin0925

·

Published

2022-05-18

·

Updated

2023-08-08

·

CVE-2022-29639

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A3100R versions V4.1.2cu.5050 B20200504 through V4.1.2cu.5247 B20211129
Description A command injection issue was discovered via the magicid parameter in the uci cloudupdate config function. This allows for potential exploitation.
Recommendations For TOTOLINK A3100R versions V4.1.2cu.5050 B20200504 through V4.1.2cu.5247 B20211129, consider restricting access to the uci cloudupdate config function until a patch is available. Avoid using the magicid parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Related Identifiers

CVE-2022-29639

Affected Products

Totolink A3100R