PT-2025-3409 · Totolink · Totolink X6000R

Published

2025-01-10

·

Updated

2025-01-15

·

CVE-2024-57211

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A6000R version V1.0.1-B20201211.2000
Description A command injection issue was discovered via the modifyOne parameter in the enable wsh function. This allows for potential exploitation.
Recommendations For TOTOLINK A6000R version V1.0.1-B20201211.2000, consider disabling the enable wsh function or restricting access to the modifyOne parameter until a patch is available.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-57211

Affected Products

Totolink X6000R