Remote Command Execution Vulnerability in TOTOLINK X5000R
CVE-2024-32350
8.8HIGH
What is CVE-2024-32350?
The TOTOLINK X5000R is affected by a vulnerability that allows authenticated remote command execution (RCE) through improper handling of the 'ipsecPsk' parameter within the 'cstecgi.cgi' binary. This weakness can enable an attacker to execute arbitrary commands on the device, potentially leading to unauthorized access and significant security risks. Users are urged to assess their device settings and followed recommended patches to safeguard against exploitation.