Lucene search

K
cveMitreCVE-2022-38826
HistorySep 16, 2022 - 3:15 p.m.

CVE-2022-38826

2022-09-1615:15:09
CWE-78
mitre
web.nvd.nist.gov
34
9
cve-2022-38826
totolink t6
arbitrary command
cstecgi.cgi
security vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.03

Percentile

91.0%

In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.

Affected configurations

Nvd
Node
totolinkt6_firmwareMatch4.1.5cu.709_b20210518
AND
totolinkt6Match3
VendorProductVersionCPE
totolinkt6_firmware4.1.5cu.709_b20210518cpe:2.3:o:totolink:t6_firmware:4.1.5cu.709_b20210518:*:*:*:*:*:*:*
totolinkt63cpe:2.3:h:totolink:t6:3:*:*:*:*:*:*:*

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.03

Percentile

91.0%

Related for CVE-2022-38826