CVE-2024-25468: OS Command Injection
Published Feb 17, 2024
·Updated
An issue in TOTOLINK X5000R V.9.1.0u.6369B20230113 allows a remote attacker to cause a denial of service via the hosttime parameter of the NTPSyncWithHost component.
Affected Software
2 affected components
All of the following
TOTOLINK X5000r Firmware=9.1.0u.6369_b20230113
TOTOLINK X5000R
Event History
Feb 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25468?
CVE-2024-25468 is classified as a denial of service vulnerability.
2
How do I fix CVE-2024-25468?
To fix CVE-2024-25468, update the TOTOLINK X5000R firmware to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2024-25468?
CVE-2024-25468 specifically affects TOTOLINK X5000R firmware version 9.1.0u.6369_B20230113.
4
Can CVE-2024-25468 be exploited remotely?
Yes, CVE-2024-25468 allows a remote attacker to exploit the vulnerability to cause a denial of service.
5
What component is vulnerable in CVE-2024-25468?
The vulnerability in CVE-2024-25468 exists in the host_time parameter of the NTPSyncWithHost component.