PT-2022-24358 · Totolink · Totolink A700Ru

Published

2022-09-14

·

Updated

2023-08-08

·

CVE-2022-38308

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLink A700RU version V7.4cu.2313 B20191024
Description A command injection issue was discovered, allowing attackers to execute arbitrary commands via a crafted payload. This issue is related to the lang parameter in the cstesystem function.
Recommendations For TOTOLink A700RU version V7.4cu.2313 B20191024, consider restricting access to the cstesystem function to minimize the risk of exploitation. Avoid using the lang parameter in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-38308

Affected Products

Totolink A700Ru