Back

HIGH

TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter

Published May 28, 2024

Description

TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 28, 2024
Updated Jul 9, 2026
Reserved May 17, 2024
CISA Vulnrichment
Updated Aug 19, 2024
NVD
Status Modified
Modified Jul 9, 2026
Red Hat
Severity n/a
Public date n/a