TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
                
            References
                    | Link | Resource | 
|---|---|
| https://doudoudedi.github.io/2022/02/21/TOTOLINK-N600R-Command-Injection/ | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2022-03-22 14:15
Updated : 2022-03-29 09:26
NVD link : CVE-2022-26189
Mitre link : CVE-2022-26189
JSON object : View
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
                totolink
- n600r_firmware
 - n600r
 


