PT-2024-3691 · Totolink · Totolink Cp450

Published

2024-05-09

·

Updated

2024-07-03

·

CVE-2024-34218

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK CP450 versions 4.1.0cu.747 B20191224
Description The issue is related to the NTPSyncWithHost function of the Request Handler component in the TOTOLINK CP450 router's firmware, which fails to properly sanitize data at the management level. This can be exploited by a remote attacker to execute arbitrary commands via the hostTime parameter.
Recommendations For version 4.1.0cu.747 B20191224, consider disabling the NTPSyncWithHost function as a temporary workaround until a patch is available. Restrict access to the hostTime parameter in the affected API endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Neutralization

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-04035
CVE-2024-34218

Affected Products

Totolink Cp450