Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33369 | A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 16 Dec 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink x18 Firmware
|
|
| CPEs | cpe:2.3:o:totolink:x18_firmware:9.1.0cu.2024_b20220329:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink x18 Firmware
|
Thu, 07 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink
Totolink x18 |
|
| CPEs | cpe:2.3:h:totolink:x18:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink
Totolink x18 |
|
| Metrics |
ssvc
|
Thu, 07 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | TOTOLINK X18 cstecgi.cgi os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-11-07T18:30:13.444Z
Reserved: 2024-11-07T11:10:23.601Z
Link: CVE-2024-10966
Updated: 2024-11-07T18:30:04.173Z
Status : Analyzed
Published: 2024-11-07T18:15:16.033
Modified: 2024-12-16T23:05:44.547
Link: CVE-2024-10966
No data.
OpenCVE Enrichment
No data.
EUVD