CVE-2024-1781: Totolink X6000R AX3000 shttpd cstecgi.cgi setWizardCfg command injection
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.85220230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1781?
CVE-2024-1781 has been rated as critical.
What component is affected by CVE-2024-1781?
CVE-2024-1781 affects the shttpd component of the Totolink X6000R AX3000 router.
What type of vulnerability is CVE-2024-1781?
CVE-2024-1781 is a command injection vulnerability.
How can I mitigate CVE-2024-1781?
To mitigate CVE-2024-1781, update the firmware of the Totolink X6000R AX3000 to the latest version provided by the vendor.
What function is exploited in CVE-2024-1781?
The vulnerability is exploited through the setWizardCfg function in the /cgi-bin/cstecgi.cgi file.