PT-2025-3411 · Totolink · Totolink X6000R

Published

2025-01-10

·

Updated

2025-01-13

·

CVE-2024-57213

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions TOTOLINK A6000R version V1.0.1-B20201211.2000
Description A command injection issue was discovered via the newpasswd parameter in the action passwd function. This allows for potential exploitation.
Recommendations For TOTOLINK A6000R version V1.0.1-B20201211.2000, consider disabling the action passwd function until a patch is available to prevent command injection via the newpasswd parameter.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-57213

Affected Products

Totolink X6000R