CVE-2024-57036
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
21/01/2025
Last modified:
29/04/2025
Description
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5032_b20200407:*:*:*:*:*:*:* | ||
cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page