CVE-2024-0579: Totolink X2000R formMapDelDevice command injection
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0579?
CVE-2024-0579 is classified as a critical vulnerability due to the potential for command injection.
How do I fix CVE-2024-0579?
To fix CVE-2024-0579, users should upgrade to a patched version of the Totolink X2000R firmware.
What systems are affected by CVE-2024-0579?
CVE-2024-0579 affects the Totolink X2000R with firmware version 1.0.0-B20221212.1452.
What type of attacks can exploit CVE-2024-0579?
CVE-2024-0579 can be exploited through command injection attacks via the formMapDelDevice function.
Who is the vendor for CVE-2024-0579?
The vendor for CVE-2024-0579 is Totolink, responsible for the X2000R router.