CVE-2022-38511
published 2022-08-29CVE-2022-38511: TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.
PriorityP277high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.32%
67.6th percentile
TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | a810r_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests targeting the downloadFile.cgi endpoint on TOTOLINK A810R devices for shell metacharacters or command injection payloads in parameters. ↗
- ·Vulnerability is confirmed only in firmware version V5.9c.4050_B20190424 of the TOTOLINK A810R; other versions are not confirmed affected by the sources. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q686-qg49-f6hm: TOTOLINK A810R V5
ghsa_unreviewed·2022-08-29
CVE-2022-38511 [HIGH] CWE-77 GHSA-q686-qg49-f6hm: TOTOLINK A810R V5
TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.
VulnCheck
totolink a810r_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2022·CVSS 7.8
CVE-2022-38511 [HIGH] totolink a810r_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
totolink a810r_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.
Affected: totolink a810r_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.fortinet.com/blog/threat-research/Iz1h9-campaign-enhances-arsenal-with-scores-of-exploits
No detection rules found.
No public exploits indexed.
arXiv
SyzTrust: State-aware Fuzzing on Trusted OS Designed for IoT Devices
arxiv_fulltext·2023-09-26
SyzTrust: State-aware Fuzzing on Trusted OS Designed for IoT Devices
SyzTrust: State-aware Fuzzing on Trusted OS Designed for IoT Devices
Qinying Wang12,
Boyu Chang1,
Shouling Ji1^( ),Shouling Ji is the corresponding author.,
Yuan Tian3,
Xuhong Zhang1,
Binbin Zhao4,
Gaoning Pan1,
Chenyang Lyu1,
Mathias Payer2,
Wenhai Wang1,
Raheem Beyah4
1Zhejiang University,
2EPFL,
3University of California, Los Angelos,
4Georgia Institute of Technology
E-mails: \wangqinying, bychang, sji\@zju.edu.cn, [email protected], [email protected], [email protected],
\pgn, puppet\@zju.edu.cn, [email protected], [email protected], [email protected]
plain
plain
IEEEexample:BSTcontrol
## Abstract
Trusted Execution Environments (TEEs) embedded in IoT devices provide a deployable solution to secure IoT applications at the hardware level.
By design, in TEEs,
Bleepingcomputer
Mirai DDoS malware variant expands targets with 13 router exploits
blogs_bleepingcomputer·2023-10-10·CVSS 9.8
[CRITICAL] Mirai DDoS malware variant expands targets with 13 router exploits
## Mirai DDoS malware variant expands targets with 13 router exploits
## Bill Toulas
A Mirai-based DDoS (distributed denial of service) malware botnet tracked as IZ1H9 has added thirteen new payloads to target Linux-based routers and routers from D-Link, Zyxel, TP-Link, TOTOLINK, and others.
Fortinet researchers report observing a peak in the exploitation rates around the first week of September, reaching tens of thousands of exploitation attempts against vulnerable devices.
IZ1H9 compromises devices to enlist them to its DDoS swarm and then launches DDoS attacks on specified targets, presumably on the order of clients renting its firepower.
## Extensive IoT targeting
The more devices and vulnerabilities targeted by a DDoS malware increased the potential to build a large and powerful
2022-08-29
Published
Exploited in the wild