EXPOSURES › CVE-2024-52723
CVE-2024-52723
CRITICAL
DETAIL
SourceNVD · cve
Published2024-11-22
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-52723 ↗
⚡ RCE
SHAME 50/100
rce
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.