PT-2024-3690 · Totolink · Totolink Cp450

Published

2024-05-09

·

Updated

2024-08-08

·

CVE-2024-34219

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK CP450 version 4.1.0cu.747 B20191224
Description The issue is related to a vulnerability in the SetTelnetCfg function, which can be exploited by attackers to log in through telnet. This vulnerability exists due to insufficient input validation in the TELNET component of the TOTOLINK CP450 router's firmware. Exploitation of this issue may allow a remote attacker to execute arbitrary code using the TELNET network protocol.
Recommendations For TOTOLINK CP450 version 4.1.0cu.747 B20191224, consider disabling the SetTelnetCfg function as a temporary workaround until a patch is available. Restrict access to the TELNET component to minimize the risk of exploitation. Avoid using the TELNET protocol until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-04034
CVE-2024-34219

Affected Products

Totolink Cp450