← volver
CVE-2024-9001mediumexplotación observadaCWE-78

TOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection

35Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck.

ssvc Attendcvss 5.3epss 3.3%
de la publicación al arma
Publicada en NVD19 sept
VulnCheck+297d
probabilidad de explotación
3.3%top 12% de las CVE
explotación observada
VulnCheck
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Productos afectados
TOTOLINK · T10