Remote Command Execution Vulnerability in TOTOLINK X5000R
CVE-2024-32350
8.8HIGH
Summary
The TOTOLINK X5000R is affected by a vulnerability that allows authenticated remote command execution (RCE) through improper handling of the 'ipsecPsk' parameter within the 'cstecgi.cgi' binary. This weakness can enable an attacker to execute arbitrary commands on the device, potentially leading to unauthorized access and significant security risks. Users are urged to assess their device settings and followed recommended patches to safeguard against exploitation.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published