PT-2024-1545 · Totolink · Totolink A3300R

Published

2024-01-30

·

Updated

2024-08-29

·

CVE-2024-24326

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3300R version V17.0.0cu.557 B20221024
Description The issue exists due to the lack of measures to neutralize special elements in the setStaticDhcpRules function of the TOTOLINK A3300R router's firmware. This allows a remote attacker to execute arbitrary commands via the arpEnable parameter in the setStaticDhcpRules function.
Recommendations For TOTOLINK A3300R version V17.0.0cu.557 B20221024, as a temporary workaround, consider disabling the setStaticDhcpRules function until a patch is available. Restrict access to the arpEnable parameter in the setStaticDhcpRules function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-01080
CVE-2024-24326

Affected Products

Totolink A3300R