CVE-2024-34218: Command Injection
Published May 14, 2024
·Updated
TOTOLINK outdoor CPE CP450 v4.1.0cu.747B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.
Affected Software
3 affected components
TOTOLINK CPE CP450
All of the following
TOTOLINK Cp450 Firmware=4.1.0cu.747_b20191224
TOTOLINK CP450
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:38 PM
Aug 2, 2024
Data Sourced
via MITRE·02:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34218?
CVE-2024-34218 has a high severity rating due to its command injection vulnerability.
2
How do I fix CVE-2024-34218?
To fix CVE-2024-34218, update your TOTOLINK CP450 firmware to the latest version provided by the manufacturer.
3
What systems are affected by CVE-2024-34218?
CVE-2024-34218 affects the TOTOLINK outdoor CPE CP450 running firmware version v4.1.0cu.747_B20191224.
4
What type of vulnerability is CVE-2024-34218?
CVE-2024-34218 is a command injection vulnerability that can be exploited via the hostTime parameter.
5
Can CVE-2024-34218 be exploited remotely?
Yes, CVE-2024-34218 can be exploited remotely if the vulnerable device is accessible over the network.