CVE-2024-37626
published 2024-06-20CVE-2024-37626: A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the…
PriorityP353high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
1.49%
71.1th percentile
A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | a6000r_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TOTOLINK A6000R .0.1-B20201211.2000 The vif_enable iface command injection
vuldb·2026-07-12·CVSS 8.8
CVE-2024-37626 [HIGH] TOTOLINK A6000R .0.1-B20201211.2000 The vif_enable iface command injection
A vulnerability was found in TOTOLINK A6000R .0.1-B20201211.2000. It has been declared as critical. Affected is the function vif_enable of the component The. The manipulation of the argument iface results in command injection.
This vulnerability was named CVE-2024-37626. The attack may be performed from remote. There is no available exploit.
GHSA
GHSA-68f4-m7ww-959w: A command injection issue in TOTOLINK A6000R V1
ghsa_unreviewed·2024-06-20
CVE-2024-37626 [HIGH] CWE-78 GHSA-68f4-m7ww-959w: A command injection issue in TOTOLINK A6000R V1
A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-20
Published