CVE-2022-28906 is a command injection vulnerability in TOTOLink N600R firmware version V5.3c.7159_B20190425. The issue is present in the /setting/setLanguageCfg endpoint, where the langtype parameter is not properly sanitized before being used in a context that allows execution of operating system commands. An attacker able to submit crafted input to this parameter can inject shell metacharacters or command content, causing unintended command execution on the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2022-28906 affecting the TOTOLINK N600R router. The repository contains four files: a README with vulnerability details and usage examples, a single executable exploit script (poc.py), a requirements.txt listing the requests dependency, and a minimal .gitignore. The exploit is not part of a larger framework. The main capability is unauthenticated remote command execution against the router’s web management interface. The script accepts a target and an arbitrary command from the command line, constructs a POST request to /cgi-bin/cstecgi.cgi, and sends a JSON body containing topicurl=setting/setLanguageCfg and langType=`<command>`. The attacker-controlled command is wrapped in backticks to trigger shell execution on the device. The script then prints the full HTTP response, making it useful as an operational PoC rather than just a detector. The exploit supports both bare host/IP input and full http:// or https:// target URLs. It crafts browser-like headers including Host, Origin, Referer, X-Requested-With, and User-Agent. TLS certificate verification is disabled (verify=False), which helps against self-signed device certificates but is operationally insecure. No authentication, brute force, or persistence logic is present; exploitation is a single request. The README demonstrates post-exploitation by injecting telnetd -p 2323 -l /bin/sh, which would expose a shell on TCP port 2323. This indicates the exploit can be used to achieve immediate command execution and simple service-based shell access if the target environment permits it. Overall, this is a concise, real exploit PoC with a customizable command payload and clear targeting of the TOTOLINK N600R vulnerable firmware.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.