PT-2024-5386 · Totolink · Totolink Cp900L

Yhryhryhr_Tu

·

Published

2024-07-23

·

Updated

2024-08-15

·

CVE-2024-7464

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK CP900 version 6.3c.566
Description A critical issue has been found in the Telnet Service component, specifically affecting the setTelnetCfg function. The manipulation of the telnet enabled argument leads to command injection. This issue can be exploited remotely by sending a specially crafted POST request. The exploit has been disclosed publicly.
Recommendations For TOTOLINK CP900 version 6.3c.566, as a temporary workaround, consider disabling the setTelnetCfg function until a patch is available. Restrict access to the Telnet Service component to minimize the risk of exploitation. Avoid using the telnet enabled argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Neutralization

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-06020
CVE-2024-7464

Affected Products

Totolink Cp900L