PT-2024-20361 · Totolink · Totolink A3300R

Published

2024-01-30

·

Updated

2024-02-02

·

CVE-2024-24327

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3300R version 17.0.0cu.557 B20221024
Description A command injection issue was discovered, which can be exploited via the pppoePass parameter in the setIpv6Cfg function. This allows attackers to inject commands, potentially leading to unauthorized access or control.
Recommendations For TOTOLINK A3300R version 17.0.0cu.557 B20221024, consider updating to a newer version that addresses this issue. As a temporary workaround, restrict access to the setIpv6Cfg function to minimize the risk of exploitation. Avoid using the pppoePass parameter in the affected function until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-24327

Affected Products

Totolink A3300R