CVE-2024-36783: Command Injection
TOTOLINK LR350 V9.3.5u.6369B20220309 was discovered to contain a command injection via the hosttime parameter in the NTPSyncWithHost function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36783?
CVE-2024-36783 has been classified as a critical vulnerability due to the potential for command injection.
How do I fix CVE-2024-36783?
To fix CVE-2024-36783, it is recommended to update the firmware of the TOTOLINK LR350 to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2024-36783?
CVE-2024-36783 specifically affects the TOTOLINK LR350 running firmware version V9.3.5u.6369_B20220309.
What impact can CVE-2024-36783 have on my device?
If exploited, CVE-2024-36783 could allow an attacker to execute arbitrary commands on the TOTOLINK LR350, compromising device security.
Is there a known exploit for CVE-2024-36783?
Yes, there are reports indicating that CVE-2024-36783 can be exploited through the host_time parameter in the NTPSyncWithHost function.