CVE-2024-33433: Medium severity totolink x2000r firmware vulnerability
Published May 14, 2024
·Updated
Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.
Affected Software
1 affected component
totolink X2000R<1.0.0-B20231213.1013
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:37 PM
Data Sourced
via NVD·03:37 PM
DescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-33433?
CVE-2024-33433 is classified as a high-severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2024-33433?
To mitigate CVE-2024-33433, update TOTOLINK X2000R to version 1.0.0-B20231213.1013 or later.
3
What type of attack is possible with CVE-2024-33433?
CVE-2024-33433 allows remote attackers to execute arbitrary code via the Guest Access Control parameter.
4
Which devices are affected by CVE-2024-33433?
CVE-2024-33433 affects the TOTOLINK X2000R router running versions prior to 1.0.0-B20231213.1013.
5
Where can I find more information about CVE-2024-33433?
Details about CVE-2024-33433 can usually be found in security advisories or the vendor's update notes.