PT-2024-5358 · Totolink · Totolink X6000R
Yanggao017
·
Published
2024-07-23
·
Updated
2024-08-01
·
CVE-2024-41319
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TOTOLINK A6000R version V1.0.1-B20201211.2000
Description
The issue is related to the
cmd parameter in the webcmd function of the TOTOLINK A6000R router's firmware, which fails to neutralize special elements used in the operating system command. This can be exploited by a remote attacker to execute arbitrary code by sending a specially crafted command.Recommendations
For version V1.0.1-B20201211.2000, as a temporary workaround, consider disabling the
webcmd function until a patch is available. Restrict access to the cmd parameter in the webcmd function to minimize the risk of exploitation. Avoid using the cmd parameter in the affected webcmd function until the issue is resolved.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink X6000R