First published: Tue Jan 21 2025(Updated: )
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TOTOLINK A810R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57036 has a severity rating that depends on the potential impact of command injection on the affected system.
To fix CVE-2024-57036, it is recommended to update to the latest firmware version provided by TOTOLINK that addresses this vulnerability.
CVE-2024-57036 is a command insertion vulnerability that allows attackers to execute arbitrary commands through crafted HTTP requests.
The vulnerability CVE-2024-57036 specifically affects the TOTOLINK A810R model running the firmware version V4.1.2cu.5032_B20200407.
Yes, CVE-2024-57036 can be exploited remotely by sending specially crafted HTTP requests to the vulnerable device.