CVE-2024-53333
published 2024-11-21CVE-2024-53333: TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to…
PriorityP350medium6.3CVSS 3.1
AVNACLPRLUIRSUCNILAH
EPSS
18.90%
97.0th percentile
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | ex200_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Totolink cstecgi.cgi setUssd ussd Parameter Command Injection Attempt (CVE-2024-53333)
suricata·2025-07-17·CVSS 6.3
CVE-2025-53333 [MEDIUM] ET WEB_SPECIFIC_APPS Totolink cstecgi.cgi setUssd ussd Parameter Command Injection Attempt (CVE-2024-53333)
ET WEB_SPECIFIC_APPS Totolink cstecgi.cgi setUssd ussd Parameter Command Injection Attempt (CVE-2024-53333)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Totolink cstecgi.cgi setUssd ussd Parameter Command Injection Attempt (CVE-2024-53333)"; flow:established,to_server; http.uri; bsize:12; content:"/cstecgi.cgi"; http.request_body; content:"|22|setUssd|22|"; fast_pattern; content:"|22|ussd|22 3a|"; pcre:"/^[^,}$]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26{2}|%26%26))+/R"; reference:url,github.com/luckysmallbird/Totolink-EX200-Vulnerability-1; reference:cve,2025-53333; reference:cve,2024-53333; classtype:attempted-admin; sid:2063551; rev:1; metadata:affected_product TOTOLINK, attack_target Networking_Equipment, tls_state pla
No public exploits indexed.
No writeups or analysis indexed.
2024-11-21
Published