CVE-2024-0579Injection in X2000r

Severity
5.3MEDIUMNVD
EPSS
0.8%
top 26.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16

Description

A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5totolink/x2000r1.0.0-B20221212.1452
NVDtotolink/x2000r_firmware1.0.0-b20221212.1452

🔴Vulnerability Details

2
GHSA
GHSA-8m2p-3j92-v9rw: A vulnerability classified as critical was found in Totolink X2000R 12024-01-16
CVEList
Totolink X2000R formMapDelDevice command injection2024-01-16
CVE-2024-0579 — Injection in Totolink X2000r | cvebase