PT-2024-3690 · Totolink · Totolink Cp450
Published
2024-05-09
·
Updated
2024-08-08
·
CVE-2024-34219
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TOTOLINK CP450 version 4.1.0cu.747 B20191224
Description
The issue is related to a vulnerability in the
SetTelnetCfg function, which can be exploited by attackers to log in through telnet. This vulnerability exists due to insufficient input validation in the TELNET component of the TOTOLINK CP450 router's firmware. Exploitation of this issue may allow a remote attacker to execute arbitrary code using the TELNET network protocol.Recommendations
For TOTOLINK CP450 version 4.1.0cu.747 B20191224, consider disabling the
SetTelnetCfg function as a temporary workaround until a patch is available. Restrict access to the TELNET component to minimize the risk of exploitation. Avoid using the TELNET protocol until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Using Hardcoded Credentials
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Totolink Cp450