Autore: Angelo Barbosa

CVE-2024-57017 | TOTOLINK X5000R 9.1.0cu.2350_B20230313 setVpnAccountCfg pass os command injection

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2350_B20230313 and classified as critical. This vulnerability affects the function setVpnAccountCfg. The manipulation of the argument pass leads to os command injection. This vulnerability was named CVE-2024-57017. The attack can be initiated remotely. There is no exploit...

Per saperne di più

CVE-2024-57018 | TOTOLINK X5000R 9.1.0cu.2350_B20230313 setVpnAccountCfg desc os command injection

A vulnerability, which was classified as critical, has been found in TOTOLINK X5000R 9.1.0cu.2350_B20230313. Affected by this issue is the function setVpnAccountCfg. The manipulation of the argument desc leads to os command injection. This vulnerability is handled as CVE-2024-57018. The attack may be launched remotely. There is no exploit...

Per saperne di più

CVE-2024-57021 | TOTOLINK X5000R 9.1.0cu.2350_B20230313 setWiFiScheduleCfg eHour os command injection

A vulnerability classified as critical was found in TOTOLINK X5000R 9.1.0cu.2350_B20230313. Affected by this vulnerability is the function setWiFiScheduleCfg. The manipulation of the argument eHour leads to os command injection. This vulnerability is known as CVE-2024-57021. The attack can be launched remotely. There is no exploit...

Per saperne di più