First published: Tue May 14 2024(Updated: )
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink CP450 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34205 has a medium severity rating due to its potential to allow unauthorized command execution.
To fix CVE-2024-34205, update the TOTOLINK CP450 firmware to a version that addresses this command injection vulnerability.
CVE-2024-34205 can allow an attacker to execute arbitrary commands on the affected TOTOLINK CP450 device.
Currently, the best workaround is to limit external access to the device until a firmware update is available.
CVE-2024-34205 specifically affects the download_firmware function in the TOTOLINK CP450.