Totolink N200RE cstecgi.cgi setTracerouteCfg os command injection
Published Jan 8, 2024
9.8
CRITICALCVSS 3.1
EPSS 3.83%
Description
A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249865 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 9.3.5u.6139_B20201216
- 9.3.5u.6139_b20201216
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16095 Advisory
- https://github.com/jylsec/vuldb/blob/main/TOTOLINK/N200RE/setTracerouteCfg/README.md broken-linkexploitThird Party Advisory
- https://vuldb.com/?ctiid.249865 signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.249865 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16095 | Advisory | |
| https://github.com/jylsec/vuldb/blob/main/TOTOLINK/N200RE/setTracerouteCfg/README.md | broken-linkexploitThird Party Advisory | |
| https://vuldb.com/?ctiid.249865 | signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?id.249865 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data