Vulnerability Description
TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | T6 Firmware | 5.9c.4085_b20190428 |
| Totolink | T6 | - |
Related Weaknesses (CWE)
References
- https://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/T6/README.mdExploitPatchThird Party Advisory
- https://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/T6/README.mdExploitPatchThird Party Advisory
FAQ
What is CVE-2022-25084?
CVE-2022-25084 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STR...
How severe is CVE-2022-25084?
CVE-2022-25084 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-25084?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink T6 Firmware, Totolink T6.