First published: Wed Mar 20 2024(Updated: )
There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink X2000R Firmware | <v1.0.0-B20231213.1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29419 is classified as a high severity Cross-site scripting (XSS) vulnerability.
To fix CVE-2024-29419, update the TOTOLINK X2000R firmware to version v1.0.0-B20231213.1013 or later.
CVE-2024-29419 affects the TOTOLINK X2000R routers running firmware versions prior to v1.0.0-B20231213.1013.
Yes, exploiting CVE-2024-29419 can allow an attacker to execute malicious scripts in the context of the user's browser.
Yes, the exploitation of CVE-2024-29419 is typically carried out through malicious user input in the Wireless settings.