cbcvebase.
CVE-2024-23061
published 2024-01-11

CVE-2024-23061: TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.

Affected

4 ranges
VendorProductVersion rangeFixed in
cesantamongoose>= 0 < 6.13.66.13.6
cesantamongoose>= 7.0.0-rc0 < 7.8.47.8.4
cesantamongoose>= 8.0.0-rc0 < 8.9.58.9.5
totolinka3300r_firmware

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.1CRITICAL