CVE-2024-57036

TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.
Configurations

No configuration.

History

04 Feb 2025, 16:15

Type Values Removed Values Added
CWE CWE-77
Summary
  • (es) Se descubrió que TOTOLINK A810R V4.1.2cu.5032_B20200407 contenía una vulnerabilidad de inserción de comandos en la función principal downloadFile.cgi. Esta vulnerabilidad permite que un atacante ejecute comandos arbitrarios mediante el envío de una solicitud HTTP.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

21 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 16:15

Updated : 2025-02-04 16:15


NVD link : CVE-2024-57036

Mitre link : CVE-2024-57036

CVE.ORG link : CVE-2024-57036


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')