Command Injection Vulnerability in TOTOLINK X6000R Router
CVE-2024-7907
9.8CRITICAL
Summary
A critical command injection vulnerability exists in the TOTOLINK X6000R router, specifically affecting the setSyslogCfg function within the /cgi-bin/cstecgi.cgi file. By manipulating the rtLogServer argument, an attacker can execute arbitrary commands on the device. This vulnerability can be exploited remotely, posing a significant risk to users. The details were disclosed publicly, prompting immediate action from cybersecurity professionals. Unfortunately, the vendor did not respond to early notifications regarding this security issue. Users of the affected product are advised to take necessary precautions, including updating their devices and monitoring for unusual activity.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database