CVE-2024-0299
Totolink N200RE cstecgi.cgi setTracerouteCfg os command injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249865 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Se encontró una vulnerabilidad en Totolink N200RE 9.3.5u.6139_B20201216. Ha sido declarada crítica. La función setTracerouteCfg del archivo /cgi-bin/cstecgi.cgi es afectada por esta vulnerabilidad. La manipulación del argumento command conduce a la inyección de comandos del sistema operativo. El ataque se puede lanzar de forma remota. La explotación ha sido divulgada al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-249865. NOTA: Se contactó primeramente al proveedor sobre esta divulgación, pero no respondió de ninguna forma.
In Totolink N200RE 9.3.5u.6139_B20201216 wurde eine kritische Schwachstelle ausgemacht. Es geht um die Funktion setTracerouteCfg der Datei /cgi-bin/cstecgi.cgi. Dank der Manipulation des Arguments command mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-07 CVE Reserved
- 2024-01-08 CVE Published
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- 2025-01-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.249865 | Technical Description |
URL | Date | SRC |
---|---|---|
https://github.com/jylsec/vuldb/blob/main/TOTOLINK/N200RE/setTracerouteCfg/README.md | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Totolink Search vendor "Totolink" | N200re Firmware Search vendor "Totolink" for product "N200re Firmware" | 9.3.5u.6139_b20201216 Search vendor "Totolink" for product "N200re Firmware" and version "9.3.5u.6139_b20201216" | - |
Affected
| in | Totolink Search vendor "Totolink" | N200re Search vendor "Totolink" for product "N200re" | - | - |
Safe
|