CVE-2024-57036

TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5032_b20200407:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:*

History

29 Apr 2025, 16:22

Type Values Removed Values Added
References () https://github.com/luckysmallbird/Totolink-A810R-Vulnerability-1/blob/main/3.md - () https://github.com/luckysmallbird/Totolink-A810R-Vulnerability-1/blob/main/3.md - Exploit, Third Party Advisory
First Time Totolink a810r
Totolink
Totolink a810r Firmware
CPE cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5032_b20200407:*:*:*:*:*:*:*

04 Feb 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió que TOTOLINK A810R V4.1.2cu.5032_B20200407 contenía una vulnerabilidad de inserción de comandos en la función principal downloadFile.cgi. Esta vulnerabilidad permite que un atacante ejecute comandos arbitrarios mediante el envío de una solicitud HTTP.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-77

21 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 16:15

Updated : 2025-04-29 16:22


NVD link : CVE-2024-57036

Mitre link : CVE-2024-57036

CVE.ORG link : CVE-2024-57036


JSON object : View

Products Affected

totolink

  • a810r
  • a810r_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')