CVE-2024-42744: OS Command Injection
In TOTOLINK X5000r v9.1.0cu.2350b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authenticated Attackers can send malicious packet to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42744?
CVE-2024-42744 is classified as a critical vulnerability due to its potential to allow authenticated attackers to execute arbitrary commands on the device.
How do I fix CVE-2024-42744?
To remediate CVE-2024-42744, update the TOTOLINK X5000r firmware to the latest version available from the manufacturer.
Who is affected by CVE-2024-42744?
Users of the TOTOLINK X5000r firmware version 9.1.0u.6369_b20230113 are affected by CVE-2024-42744.
What type of vulnerability is CVE-2024-42744?
CVE-2024-42744 is an OS command injection vulnerability found in the file /cgi-bin/cstecgi.cgi.
Can CVE-2024-42744 be exploited remotely?
Yes, CVE-2024-42744 can be exploited by authenticated attackers who send malicious packets to the affected device.