References https://nvd.nist.gov/vuln/detail/cve-2022-28584 https://www.nsfocus.net/vulndb/64623 https://avd.aliyun.com/detail?id=AVD-2022-28584 https://zone.ci/aliyun/ali_nvd/61585.html https://www.variotdbs.pl/vuln/VAR-202205-0051 https://advisories.checkpoint.com/defense/advisories/public/2022/cpai-2022-0886.html https://cve.komodosec.com/cve-list.php?search=&cvss_score_range=9&year=&has_exploit=&results_per_page=15&sort=cvss_score2&order=ascending&page_number=2033 https://feedly.com/cve/CVE-2022-28584 https://vulners.com/search/vendors/totolink/products/a7100ru%20firmware?month=12 https://cve.imfht.com/detail/CVE-2022-28584 https://bbs.kanxue.com/thread-273945.htm
Related VulnerabilitiesTOTOLINK EX200 /cgi-bin/cstecgi.cgi setLanguageCfg 命令执行漏洞TOTOLINK EX200 /cgi-bin/cstecgi.cgi NTPSyncWithHost 命令执行漏洞PoCCVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information DisclosurePoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-42887: TOTOLINK EX1200T 4.1.2cu.5215 - Authentication BypassPoCCVE-2022-25082: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-30013: TOTOLink - Unauthenticated Command InjectionPoCCVE-2023-46574: TOTOLINK A3700R - Command InjectionPoCCVE-2024-24328: TotoLink Router setMacFilterRules - Command InjectionPoCCVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection