CVE-2024-42748: OS Command Injection
In TOTOLINK X5000r v9.1.0cu.2350b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42748?
CVE-2024-42748 is classified as a critical severity vulnerability due to its ability to execute arbitrary OS commands.
How do I fix CVE-2024-42748?
To fix CVE-2024-42748, update the TOTOLINK X5000R firmware to the latest version provided by the vendor.
Who is affected by CVE-2024-42748?
CVE-2024-42748 affects users running TOTOLINK X5000R firmware version 9.1.0cu.2350_b20230313 and earlier versions.
What are the potential consequences of CVE-2024-42748?
Exploitation of CVE-2024-42748 can lead to unauthorized command execution on the affected device.
Is authentication required to exploit CVE-2024-42748?
Yes, CVE-2024-42748 requires an authenticated attacker to exploit the OS command injection vulnerability.