CVE-2024-24331: Command Injection
TOTOLINK A3300R V17.0.0cu.557B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK A3300Rto a version that resolves this vulnerability.Fixed in V17.0.0cu.557_B20221024
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24331?
CVE-2024-24331 is considered a high-severity command injection vulnerability that poses significant risks to affected systems.
How do I fix CVE-2024-24331?
To fix CVE-2024-24331, users should update the TOTOLINK A3300R firmware to the latest version that addresses this vulnerability.
What is the affected software version for CVE-2024-24331?
CVE-2024-24331 specifically affects the TOTOLINK A3300R firmware version 17.0.0cu.557_B20221024.
Who is affected by CVE-2024-24331?
Users of the TOTOLINK A3300R router running the specified firmware version are affected by CVE-2024-24331.
What type of vulnerability is CVE-2024-24331?
CVE-2024-24331 is classified as a command injection vulnerability that can be exploited through the enable parameter during WiFi schedule configuration.