CVE-2024-22529: Command Injection
Published Jan 25, 2024
·Updated
TOTOLINK X2000RV2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub449040 (handle function of formUploadFile) of /bin/boa.
Affected Software
2 affected components
All of the following
TOTOLINK X2000r Firmware=2.0.0-b20230727.10434
TOTOLINK X2000R=v2
Event History
Jan 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22529?
CVE-2024-22529 has been classified as a critical severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2024-22529?
To mitigate CVE-2024-22529, it is recommended to update the TOTOLINK X2000R firmware to the latest patched version.
3
Which devices are affected by CVE-2024-22529?
CVE-2024-22529 affects the TOTOLINK X2000R with firmware version 2.0.0-B20230727.10434.
4
What type of vulnerability is CVE-2024-22529?
CVE-2024-22529 is a command injection vulnerability that occurs in the file upload handling function.
5
Can CVE-2024-22529 lead to remote code execution?
Yes, CVE-2024-22529 can potentially allow attackers to execute arbitrary commands on the device remotely.