cve/2022/CVE-2022-28491.md
2024-06-18 02:51:15 +02:00

723 B

CVE-2022-28491

Description

TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

POC

Reference

Github

No PoCs found on GitHub currently.