CVE-2024-34210: Command Injection
Published May 14, 2024
·Updated
TOTOLINK outdoor CPE CP450 v4.1.0cu.747B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.
Affected Software
1 affected component
TOTOLINK CPE CP450
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:38 PM
Data Sourced
via NVD·03:38 PM
DescriptionSeverityWeakness
Aug 2, 2024
Data Sourced
via MITRE·02:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34210?
CVE-2024-34210 is classified as a critical severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2024-34210?
To fix CVE-2024-34210, update the TOTOLINK CPE CP450 to the latest firmware version that addresses this vulnerability.
3
What is the impact of CVE-2024-34210?
The impact of CVE-2024-34210 may allow an attacker to execute arbitrary commands on the affected device.
4
Which devices are affected by CVE-2024-34210?
CVE-2024-34210 affects the TOTOLINK CPE CP450 outdoor model running firmware version v4.1.0cu.747_B20191224.
5
What function is vulnerable in CVE-2024-34210?
The vulnerability in CVE-2024-34210 is found in the CloudACMunualUpdate function via the FileName parameter.