CVE-2024-35397: Command Injection
TOTOLINK CP900L v4.1.5cu.798B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35397?
CVE-2024-35397 is classified as a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2024-35397?
To fix CVE-2024-35397, you should update the TOTOLINK CP900L firmware to a patched version that addresses the command injection vulnerability.
What type of vulnerability is CVE-2024-35397?
CVE-2024-35397 is a command injection vulnerability found in the NTPSyncWithHost function of the TOTOLINK CP900L.
What is affected by CVE-2024-35397?
CVE-2024-35397 affects the TOTOLINK CP900L firmware version 4.1.5cu.798_B20221228.
Can CVE-2024-35397 be exploited remotely?
Yes, CVE-2024-35397 can be exploited remotely if an attacker sends a crafted request to the vulnerable NTPSyncWithHost function.