CVE-2022-28495
Description
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Command injection in TOTOLink CP900 outdoor CPE allows remote attackers to execute arbitrary commands.
Vulnerability
The TOTOLink outdoor CPE CP900 firmware version V6.3c.566_B20171026 contains a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. The function fails to sanitize user-supplied input, allowing an attacker to inject arbitrary system commands. Affected versions include V6.3c.566_B20171026 and possibly earlier ones [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable endpoint, passing malicious command strings in the webWlanIdx parameter. No authentication is required if the device's web interface is exposed. The attacker must have network access to the device's management interface [1].
Impact
Successful exploitation grants the attacker arbitrary command execution with root privileges on the device. This can lead to full compromise of the device, including data exfiltration, installation of malware, or use of the device as a pivot for further attacks [1].
Mitigation
As of the publication date (March 2023), no official patch or firmware update has been released by TOTOLink to address this vulnerability. Users should restrict access to the web interface to trusted networks and monitor for vendor updates. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- TOTOLink/outdoor CPE CP900description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.