PT-2024-24525 · Totolink · Totolink X5000R

Published

2024-05-14

·

Updated

2024-07-03

·

CVE-2024-32349

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK X5000R version 9.1.0cu.2350 B20230313
Description The issue is related to an authenticated remote command execution via the mtu parameters in the "cstecgi.cgi" binary.
Recommendations For version 9.1.0cu.2350 B20230313, consider restricting access to the "cstecgi.cgi" binary to minimize the risk of exploitation. Avoid using the mtu parameters in the affected binary until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-32349

Affected Products

Totolink X5000R