Critical severity9.8NVD Advisory· Published May 5, 2022· Updated Jun 17, 2026
CVE-2022-28578
CVE-2022-28578
Description
It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Affected products
3- cpe:2.3:o:totolink:a7100ru_firmware:7.4cu.2313_b20191024:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/EPhaha/IOT_vuln/tree/main/TOTOLink/A7100RU/2nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.