CVE-2024-34205: Command Injection
Published May 14, 2024
·Updated
TOTOLINK CP450 v4.1.0cu.747B20191224 was discovered to contain a command injection vulnerability in the downloadfirmware function.
Affected Software
1 affected component
TOTOLINK CP450
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:38 PM
Data Sourced
via NVD·03:38 PM
DescriptionSeverityWeakness
Aug 2, 2024
Data Sourced
via MITRE·02:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34205?
CVE-2024-34205 has a medium severity rating due to its potential to allow unauthorized command execution.
2
How do I fix CVE-2024-34205?
To fix CVE-2024-34205, update the TOTOLINK CP450 firmware to a version that addresses this command injection vulnerability.
3
What impact does CVE-2024-34205 have on TOTOLINK CP450?
CVE-2024-34205 can allow an attacker to execute arbitrary commands on the affected TOTOLINK CP450 device.
4
Is there a workaround for CVE-2024-34205 if I cannot update my device?
Currently, the best workaround is to limit external access to the device until a firmware update is available.
5
What functions are affected by CVE-2024-34205 in TOTOLINK CP450?
CVE-2024-34205 specifically affects the download_firmware function in the TOTOLINK CP450.