CVE-2024-23058
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 11, 2024
Updated: Jan 18, 2024
CWE ID 78
Summary
CVE-2024-23058 is a newly identified vulnerability affecting the TOTOLINK A3300R V17.0.0cu.557_B20221024 firmware. This issue allows an attacker to inject arbitrary commands through the pass parameter in the setTr069Cfg function. Successful exploitation could result in unauthorized access, data theft, or system damage. Users are advised to update their firmware as soon as a patch becomes available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- TOTOLINK