CVE-2022-28491
EUVD-2022-3293323.03.2023, 15:15
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| totolink | cp900_firmware | 6.3c.566_b20171026:c.566_b20171026 |
𝑥
= Vulnerable software versions