CVE-2024-32355: Command Injection
Published May 14, 2024
·Updated
TOTOLINK X5000R V9.1.0cu.2350B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.
Affected Software
3 affected components
TOTOLINK X5000R
All of the following
TOTOLINK X5000r Firmware=9.1.0cu.2350_b20230313
TOTOLINK X5000R
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·04:17 PM
Aug 2, 2024
Data Sourced
via MITRE·02:13 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-32355?
CVE-2024-32355 is classified as a high severity command injection vulnerability.
2
How do I fix CVE-2024-32355?
To fix CVE-2024-32355, update the TOTOLINK X5000R firmware to the latest version provided by the manufacturer.
3
What causes the vulnerability CVE-2024-32355?
CVE-2024-32355 is caused by improper validation of the 'password' parameter in the setSSServer function.
4
Can CVE-2024-32355 lead to remote code execution?
Yes, CVE-2024-32355 can potentially allow remote code execution on the affected device.
5
Which devices are affected by CVE-2024-32355?
CVE-2024-32355 affects the TOTOLINK X5000R running firmware version V9.1.0cu.2350_B20230313.