CVE-2024-52723

In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.1041_b20240224:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:*

History

16 Dec 2024, 22:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Totolink x6000r
Totolink
Totolink x6000r Firmware
Summary
  • (es) En TOTOLINK X6000R V9.4.0cu.1041_B20240224, en el archivo shttpd, se utiliza la función Uci_Set Str sin un filtrado estricto de parámetros. Un atacante puede lograr la ejecución arbitraria de comandos mediante la construcción de el payload.
References () http://x6000r.com - () http://x6000r.com - Broken Link
References () https://gist.github.com/M4rg4tr01d/e84f8ed8dc27960d7c56ad289f6fb0ff - () https://gist.github.com/M4rg4tr01d/e84f8ed8dc27960d7c56ad289f6fb0ff - Third Party Advisory
CPE cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.1041_b20240224:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:*
CWE CWE-78

22 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-22 16:15

Updated : 2025-03-13 18:15


NVD link : CVE-2024-52723

Mitre link : CVE-2024-52723

CVE.ORG link : CVE-2024-52723


JSON object : View

Products Affected

totolink

  • x6000r_firmware
  • x6000r
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')