Vulnerability Details CVE-2022-28580
It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.209
EPSS Ranking 95.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2022-28580
-
cpe:2.3:h:totolink:a7100ru:-
-
cpe:2.3:o:totolink:a7100ru_firmware:7.4cu.2313_b20191024