CVE-2024-42736
13.08.2024, 14:15
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
Vendor | Product | Version |
---|---|---|
totolink | x5000r_firmware | 9.1.0cu.2350_b20230313:cu.2350_b20230313 |
𝑥
= Vulnerable software versions