CVE-2024-32351: OS Command Injection
TOTOLINK X5000R V9.1.0cu.2350B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32351?
CVE-2024-32351 is classified as a high severity vulnerability due to its capability to allow authenticated remote command execution.
How do I fix CVE-2024-32351?
To mitigate CVE-2024-32351, it is recommended to update the TOTOLINK X5000R firmware to the latest version provided by the vendor.
Is CVE-2024-32351 exploitable remotely?
Yes, CVE-2024-32351 is an authenticated remote command execution vulnerability that can be exploited from a remote location.
What device versions are affected by CVE-2024-32351?
CVE-2024-32351 affects the TOTOLINK X5000R firmware version V9.1.0cu.2350_B20230313.
What action should be taken if I am using the affected version of TOTOLINK X5000R?
If using the affected version, it is crucial to update the firmware immediately to reduce the risk associated with CVE-2024-32351.