CVE-2022-28575: Totolink a7100ru Firmware

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload

Affected products

  • Totolink a7100ru Firmware: version 7.4cu.2313_b20191024 only

Published 2022-05-05. Last modified 2026-06-17.