8.8
CVSSv3

CVE-2024-9001

CVSSv4: 5.3 | CVSSv3: 8.8 | CVSSv2: 6.5 | VMScore: 630 | EPSS: 0.01207 | KEV: Not Included
Published: 19/09/2024 Updated: 24/09/2024

Vulnerability Summary

Critical Remote Command Injection in TOTOLINK T10 Router

An important vulnerability is in TOTOLINK T10 4.1.8cu.5207. This issue is critical. It impacts the setTracerouteCfg function in the /cgi-bin/cstecgi.cgi file. The problem is with the command argument, which leads to OS command injection. An attacker can use this remotely. The exploit is public and can be used by anyone. The vendor was informed early but did not respond.

Vulnerable Product Search on Vulmon Subscribe to Product

totolink t10 firmware 4.1.8cu.5207