PT-2022-27149 · Totolink · Totolink Nr1800X

Published

2022-11-23

·

Updated

2023-08-08

·

CVE-2022-44250

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK NR1800X version 9.1.0u.6279 B20210910
Description The issue concerns a command injection via the hostName parameter in the setOpModeCfg function. This allows for potential exploitation. No information is provided about the estimated number of affected devices or real-world incidents.
Recommendations For TOTOLINK NR1800X version 9.1.0u.6279 B20210910, consider restricting access to the setOpModeCfg function to minimize the risk of exploitation. Avoid using the hostName parameter in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-44250

Affected Products

Totolink Nr1800X