PT-2022-23797 · Totolink · Totolink A7000R

Published

2022-08-25

·

Updated

2023-08-08

·

CVE-2022-37082

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A7000R version 9.1.0u.6115 B20201022
Description A command injection issue was found via the host time parameter at the NTPSyncWithHost function, allowing for potential exploitation.
Recommendations For TOTOLINK A7000R version 9.1.0u.6115 B20201022, avoid using the host time parameter in the affected function until a fix is available. As a temporary workaround, consider restricting access to the NTPSyncWithHost function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-37082

Affected Products

Totolink A7000R