PT-2024-38120 · Totolink · Totolink A3100R

Yhryhryhr_Tu

·

Published

2024-07-28

·

Updated

2024-08-08

·

CVE-2024-7158

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3100R version 4.1.2cu.5050 B20200504
Description A critical issue affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi in the HTTP POST Request Handler component. The manipulation of the telnet enabled argument leads to command injection. This issue can be initiated remotely. The exploit has been disclosed publicly.
Recommendations For TOTOLINK A3100R version 4.1.2cu.5050 B20200504, as a temporary workaround, consider disabling the setTelnetCfg function until a patch is available. Restrict access to the /cgi-bin/cstecgi.cgi file to minimize the risk of exploitation. Avoid using the telnet enabled argument in the affected HTTP POST Request Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-7158

Affected Products

Totolink A3100R