CVE-2024-31807: Code Injection
Published Apr 8, 2024
·Updated
TOTOLINK EX200 V4.0.3c.7646B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.
Affected Software
3 affected components
TOTOLINK EX200
All of the following
TOTOLINK Ex200 Firmware=4.0.3c.7646_b20201211
TOTOLINK EX200
Event History
Apr 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31807?
CVE-2024-31807 is considered a high severity vulnerability due to its potential for remote code execution.
2
How does CVE-2024-31807 allow for exploitation?
CVE-2024-31807 can be exploited through the hostTime parameter in the NTPSyncWithHost function.
3
What products are affected by CVE-2024-31807?
CVE-2024-31807 affects the TOTOLINK EX200 router.
4
How can I fix CVE-2024-31807?
The fix for CVE-2024-31807 involves updating the firmware of the TOTOLINK EX200 to the latest version that addresses the vulnerability.
5
Is CVE-2024-31807 a common vulnerability?
CVE-2024-31807 is not widely reported but poses significant risks for users of the affected devices.