CVE-2024-42736: OS Command Injection
In TOTOLINK X5000r v9.1.0cu.2350b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42736?
CVE-2024-42736 is categorized as a high severity vulnerability due to its ability to allow command injection.
How do I fix CVE-2024-42736?
To mitigate CVE-2024-42736, users should update their TOTOLINK X5000r firmware to the latest version released by the vendor.
What type of vulnerability is CVE-2024-42736?
CVE-2024-42736 is an OS command injection vulnerability located in the addBlacklist function.
Who is affected by CVE-2024-42736?
Users of the TOTOLINK X5000r router running firmware version v9.1.0cu.2350_b20230313 are affected by CVE-2024-42736.
What can an attacker do with CVE-2024-42736?
An authenticated attacker can exploit CVE-2024-42736 to execute arbitrary OS commands on the vulnerable device.