← voltar
CVE-2024-7214

TOTOLINK LR350 cstecgi.cgi setWanCfg command injection

CVSS 5.3 MEDIUMEPSS 3.2%CWE-77
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.3EPSS 3.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
30 jul 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272785 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Produtos afetados
TOTOLINK · LR350

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →