CVE-2024-0297

HIGH EXPLOITED

Totolink N200RE 9.3.5u.6139_B20201216 - OS Command Injection via UploadFirmwareFile FileName Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-0297 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249863. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (3)

Core 3
Core References
Permissions Required, Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.249863
Permissions Required, Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.249863

Scores

CVSS v3 7.3
EPSS 0.0090
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2025-07-13
CWE
CWE-78
Status published
Products (1)
totolink/n200re_firmware 9.3.5u.6139_b20201216
Published Jan 08, 2024
Tracked Since Feb 18, 2026