CVE-2024-27521: OS Command Injection
TOTOLINK A3300R V17.0.0cu.557B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail, exploitation allows unauthenticated, remote attackers to execute arbitrary system commands with administrative privileges (i.e., as user "root").
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27521?
CVE-2024-27521 is classified as a critical vulnerability due to its potential for unauthenticated remote command execution.
How do I fix CVE-2024-27521?
To mitigate CVE-2024-27521, it is recommended to update the TOTOLINK A3300R firmware to the latest version provided by the vendor.
What devices are affected by CVE-2024-27521?
CVE-2024-27521 specifically affects the TOTOLINK A3300R router model running version V17.0.0cu.557_B20221024.
What can an attacker do if they exploit CVE-2024-27521?
Exploitation of CVE-2024-27521 allows an attacker to gain complete control over the TOTOLINK A3300R device and execute arbitrary commands.
Is there a workaround for CVE-2024-27521 if I cannot update immediately?
As a temporary workaround for CVE-2024-27521, it is advisable to restrict access to the device's management interface from untrusted networks.