CVE-2024-32349: Command Injection
TOTOLINK X5000R V9.1.0cu.2350B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32349?
CVE-2024-32349 is classified as a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2024-32349?
To mitigate CVE-2024-32349, it is recommended to update the TOTOLINK X5000R to the latest firmware version provided by the manufacturer.
What does CVE-2024-32349 exploit?
CVE-2024-32349 exploits an authenticated remote command execution vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.
Who is affected by CVE-2024-32349?
The affected product for CVE-2024-32349 is the TOTOLINK X5000R running firmware version V9.1.0cu.2350_B20230313.
Is CVE-2024-32349 reversible?
Once exploited, the changes made through CVE-2024-32349 may not be reversible without restoring the device to factory settings.