Critical severity9.8NVD Advisory· Published May 5, 2022· Updated Jun 17, 2026
CVE-2022-28575
CVE-2022-28575
Description
It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload
Affected products
3- cpe:2.3:o:totolink:a7100ru_firmware:7.4cu.2313_b20191024:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/EPhaha/IOT_vuln/tree/main/TOTOLink/A7100RU/1nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.