Show filters
610 Total Results
Displaying 31-40 of 610
Sort by:
Attacker Value
Unknown
CVE-2024-7908
Disclosure Date: August 18, 2024 (last updated August 20, 2024)
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected is the function setDefResponse of the file /www/cgi-bin/cstecgi.cgi. The manipulation of the argument IpAddress leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-7907
Disclosure Date: August 18, 2024 (last updated August 20, 2024)
A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument rtLogServer leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-42967
Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
0
Attacker Value
Unknown
CVE-2024-42966
Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
0
Attacker Value
Unknown
CVE-2024-42739
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2024-42738
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2024-42737
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2024-42748
Disclosure Date: August 12, 2024 (last updated August 14, 2024)
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2024-42747
Disclosure Date: August 12, 2024 (last updated August 14, 2024)
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2024-42745
Disclosure Date: August 12, 2024 (last updated August 14, 2024)
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
0