VYPR
Unrated severityNVD Advisory· Published Mar 24, 2023· Updated Feb 20, 2025

CVE-2022-28495

CVE-2022-28495

Description

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection in TOTOLink CP900 outdoor CPE allows remote attackers to execute arbitrary commands.

Vulnerability

The TOTOLink outdoor CPE CP900 firmware version V6.3c.566_B20171026 contains a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. The function fails to sanitize user-supplied input, allowing an attacker to inject arbitrary system commands. Affected versions include V6.3c.566_B20171026 and possibly earlier ones [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable endpoint, passing malicious command strings in the webWlanIdx parameter. No authentication is required if the device's web interface is exposed. The attacker must have network access to the device's management interface [1].

Impact

Successful exploitation grants the attacker arbitrary command execution with root privileges on the device. This can lead to full compromise of the device, including data exfiltration, installation of malware, or use of the device as a pivot for further attacks [1].

Mitigation

As of the publication date (March 2023), no official patch or firmware update has been released by TOTOLink to address this vulnerability. Users should restrict access to the web interface to trusted networks and monitor for vendor updates. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • TOTOLink/outdoor CPE CP900description
  • Range: = V6.3c.566_B20171026

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.