CVE-2024-34921: Command Injection
Published May 14, 2024
·Updated
TOTOLINK X5000R v9.1.0cu.2350B20230313 was discovered to contain a command injection via the disconnectVPN function.
Affected Software
3 affected components
TOTOLINK X5000R
All of the following
TOTOLINK X5000r Firmware=9.1.0cu.2350_b20230313
TOTOLINK X5000R
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:39 PM
Aug 2, 2024
Data Sourced
via MITRE·03:08 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34921?
CVE-2024-34921 is rated as a high severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2024-34921?
To resolve CVE-2024-34921, users should update the TOTOLINK X5000R firmware to the latest version provided by the vendor.
3
What is the impact of CVE-2024-34921?
The impact of CVE-2024-34921 includes unauthorized execution of commands on the affected device, which may compromise the system.
4
Is CVE-2024-34921 specific to a firmware version?
Yes, CVE-2024-34921 specifically affects TOTOLINK X5000R firmware version 9.1.0cu.2350_B20230313.
5
How was CVE-2024-34921 discovered?
CVE-2024-34921 was discovered through security analysis that revealed a command injection vulnerability in the disconnectVPN function.