CVE-2024-42736

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:x5000r_firmware:9.1.0cu.2350_b20230313:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x5000r:-:*:*:*:*:*:*:*

History

04 Apr 2025, 14:35

Type Values Removed Values Added
Summary
  • (es) En TOTOLINK X5000r v9.1.0cu.2350_b20230313, el archivo /cgi-bin/cstecgi.cgi contiene una vulnerabilidad de inyección de comandos del sistema operativo en addBlacklist. Los atacantes autenticados pueden enviar paquetes maliciosos para ejecutar comandos arbitrarios.
First Time Totolink
Totolink x5000r
Totolink x5000r Firmware
References () https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/addBlacklist/addBlacklist.md - () https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/addBlacklist/addBlacklist.md - Exploit, Third Party Advisory
CPE cpe:2.3:o:totolink:x5000r_firmware:9.1.0cu.2350_b20230313:*:*:*:*:*:*:*
cpe:2.3:h:totolink:x5000r:-:*:*:*:*:*:*:*

13 Aug 2024, 16:35

Type Values Removed Values Added
CWE CWE-78
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

13 Aug 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-13 14:15

Updated : 2025-04-04 14:35


NVD link : CVE-2024-42736

Mitre link : CVE-2024-42736

CVE.ORG link : CVE-2024-42736


JSON object : View

Products Affected

totolink

  • x5000r_firmware
  • x5000r
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')