← Back to browse · API

CVE-2022-28495

Severity
CRITICAL
CVSS
9.8
EPSS
0.02441
Risk score
40.05
CISA KEV
No
PoC
No
Published
2023-03-24
Modified
2025-02-20
First seen
2026-08-07
Aliases
EUVD-2022-32937, GHSA-3P4R-X5MR-F32G
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-32937

Description

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

References