S4E just found a high webmin panel detection scanner
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-25082 Scanner

CVE-2022-25082 scanner - Command Injection vulnerability in TOTOLink A950RG

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-25082
9.8
CVSS

TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The TOTOLink A950RG is a wireless router designed for home and office use. It is a powerful device that delivers high-speed internet connectivity and allows seamless access to multiple devices simultaneously. The router is equipped with advanced features, including parental control, guest network access, and VPN support, among others. Its primary function is to provide a reliable and secure network connection to users, but recently, a critical vulnerability was discovered in the product that threatens the security of the network and connected devices.

CVE-2022-25082 is a command injection vulnerability identified in the "Main" function of the TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 routers. The vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. An attacker can exploit this vulnerability remotely, gain administrative privileges, and compromise the entire network. This vulnerability poses a significant risk to users as the attacker can remotely control the network, intercept confidential data, and launch other malicious activities.

When exploited, CVE-2022-25082 can lead to disastrous consequences. Attackers can steal sensitive information such as passwords, credit card details, and personal data. They can also modify the network settings, install malware, and launch attacks on other networks. In the worst-case scenario, the attacker can gain complete control over the network, leading to the disruption of services and causing huge financial losses.

s4e.io provides expert guidance and insights into the latest vulnerabilities discovered in digital assets. It offers a comprehensive platform that provides real-time information on the latest threats, alerts, and updates. Through its pro features, users can effortlessly ascertain the security posture of their networks and identify vulnerabilities in their digital assets. By subscribing to their services, users can stay updated with the latest security trends and take proactive measures to protect their networks and devices from malicious activities.

 

REFERENCES

Solution Advice

Users of TOTOLink A950RG can take certain precautions to protect their networks from this vulnerability. Some of the measures they can take include:

  • Installing the latest firmware updates provided by TOTOLink to minimize the risk of exploitation.
  • Setting a strong and unique password for their router and Wi-Fi network.
  • Enabling the firewall and intrusion detection system on their network.
  • Disabling remote administration and UPnP if not needed.
  • Separating the network into different subnets to minimize the risk of lateral movement.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-25082 scanner - Command Injection vulnerability in TOTOLink A950RG S4E