Description
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46036 | In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload. |
References
History
Mon, 16 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink x6000r
|
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink x6000r
|
|
| Metrics |
cvssV3_1
|
Mon, 25 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink
Totolink x6000r Firmware |
|
| CPEs | cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.1041_b20240224:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink
Totolink x6000r Firmware |
|
| Metrics |
ssvc
|
Fri, 22 Nov 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-13T17:36:37.395Z
Reserved: 2024-11-15T00:00:00.000Z
Link: CVE-2024-52723
Updated: 2024-11-25T20:45:27.389Z
Status : Modified
Published: 2024-11-22T16:15:33.983
Modified: 2025-03-13T18:15:45.350
Link: CVE-2024-52723
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD