Record summary

CVE-2024-1781 has a selected CVSS score of 6.3 (medium); EIP currently links 1 repository PoC.

Description

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 9, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 25, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
CVE List9.4.0cu.852_20230719affected

Default status: unknown

CVE List9.4.0cu.852_20230719affected

Default status: unknown

CVE List9.4.0cu.852_20230719affected
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubIcycu123/CVE-2024-1781Repository PoCby Icycu123Stars: 0Not analyzed8 files

2.0 MiB

GitHub

PoC details

References

4