CVE-2024-34204: Command Injection
Published May 14, 2024
·Updated
TOTOLINK outdoor CPE CP450 v4.1.0cu.747B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.
Affected Software
1 affected component
TOTOLINK CPE CP450
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:38 PM
Data Sourced
via NVD·03:38 PM
DescriptionSeverityWeakness
Aug 2, 2024
Data Sourced
via MITRE·02:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34204?
CVE-2024-34204 is considered to be a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-34204?
To fix CVE-2024-34204, update the TOTOLINK outdoor CPE CP450 to the latest firmware version provided by the vendor.
3
What type of vulnerability is CVE-2024-34204?
CVE-2024-34204 is classified as a command injection vulnerability affecting the setUpgradeFW function.
4
What are the risks associated with CVE-2024-34204?
The risks associated with CVE-2024-34204 include unauthorized access and control over the affected device.
5
Which devices are affected by CVE-2024-34204?
CVE-2024-34204 affects the TOTOLINK outdoor CPE CP450 version 4.1.0cu.747_B20191224.