CVE-2022-25136
published 2022-02-19CVE-2022-25136: A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.20%
80.5th percentile
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | t10_firmware | — | — |
| totolink | t6_firmware | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6wc8-j6cc-j854: A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4
ghsa_unreviewed·2022-02-20
CVE-2022-25136 [CRITICAL] CWE-77 GHSA-6wc8-j6cc-j854: A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4
A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.
BSD
FreeBSD-SA-23:02.openssh: OpenSSH pre-authentication double free
bsd_advisories·2023-02-16·CVSS 6.5
CVE-2023-25136 [MEDIUM] FreeBSD-SA-23:02.openssh: OpenSSH pre-authentication double free
FreeBSD-SA-23:02.openssh Security Advisory
The FreeBSD Project
Topic: OpenSSH pre-authentication double free
Category: contrib
Module: openssh
Announced: 2023-02-16
Credits: Mantas Mikulenas
Affects: FreeBSD 12.4
Corrected: 2023-02-08 21:06:22 UTC (stable/13, 13.2-STABLE)
2023-02-08 21:07:30 UTC (stable/12, 12.4-STABLE)
2023-02-16 18:04:07 UTC (releng/12.4, 12.4-RELEASE-p2)
CVE Name: CVE-2023-25136
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
0. Revision History
v1.0 2023-02-16 -- Initial release
v1.1 2022-03-01 -- Corrected stable/13 Correction details
I. Background
OpenSSH is an implementation of the SSH protocol suite, providing an
encrypted and authenticate
No detection rules found.
No public exploits indexed.
2022-02-19
Published