First published: Tue May 14 2024(Updated: )
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK CPE CP450 | ||
All of | ||
Totolink CP450 Firmware | =4.1.0cu.747_b20191224 | |
Totolink CP450 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34218 has a high severity rating due to its command injection vulnerability.
To fix CVE-2024-34218, update your TOTOLINK CP450 firmware to the latest version provided by the manufacturer.
CVE-2024-34218 affects the TOTOLINK outdoor CPE CP450 running firmware version v4.1.0cu.747_B20191224.
CVE-2024-34218 is a command injection vulnerability that can be exploited via the hostTime parameter.
Yes, CVE-2024-34218 can be exploited remotely if the vulnerable device is accessible over the network.