← back
CVE-2024-0297highobserved exploitationCWE-78

Totolink N200RE cstecgi.cgi UploadFirmwareFile os command injection

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 7.3epss 3.8%
from disclosure to weapon
Published on NVDJan 8
VulnCheck+552d
exploitation probability
3.8%top 10% of all CVEs
observed exploitation
yesVulnCheck
A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249863. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
Totolink · N200RE