CVE-2024-57024: OS Command Injection
TOTOLINK X5000R V9.1.0cu.2350B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57024?
CVE-2024-57024 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2024-57024?
To fix CVE-2024-57024, update the TOTOLINK X5000R firmware to a version that addresses the OS command injection vulnerability.
What could an attacker achieve by exploiting CVE-2024-57024?
An attacker exploiting CVE-2024-57024 could execute arbitrary OS commands on the affected device, potentially leading to full system compromise.
Is my TOTOLINK X5000R affected by CVE-2024-57024?
If you are using the TOTOLINK X5000R with the firmware version V9.1.0cu.2350_B20230313 or earlier, your device is affected by CVE-2024-57024.
What is the nature of the vulnerability CVE-2024-57024?
CVE-2024-57024 is an OS command injection vulnerability, which allows attackers to inject and execute commands through the "eMinute" parameter.