CVE-2024-24330: Command Injection
TOTOLINK A3300R V17.0.0cu.557B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK A3300Rto a version that resolves this vulnerability.Fixed in V17.0.0cu.557_B20221024
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24330?
CVE-2024-24330 is classified as a command injection vulnerability which can potentially lead to system compromise.
How do I fix CVE-2024-24330?
To fix CVE-2024-24330, update the TOTOLINK A3300R firmware to a version that patches this command injection vulnerability.
What is the affected version of TOTOLINK A3300R in CVE-2024-24330?
The affected version of TOTOLINK A3300R in CVE-2024-24330 is V17.0.0cu.557_B20221024.
What is the nature of the vulnerability in CVE-2024-24330?
CVE-2024-24330 is a command injection vulnerability that occurs via the port or enable parameter in the setRemoteCfg function.
Can CVE-2024-24330 be exploited remotely?
Yes, CVE-2024-24330 can potentially be exploited remotely due to the nature of command injection.