CVE-2024-27521

HIGH

TOTOLINK A3300R V17.0.0cu.557_B20221024 - RCE

Title source: llm
STIX 2.1

Description

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail, exploitation allows unauthenticated, remote attackers to execute arbitrary system commands with administrative privileges (i.e., as user "root").

Scores

CVSS v3 8.0
EPSS 0.0177
EPSS Percentile 82.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
totolink/a3300r_firmware 17.0.0cu.557_b20221024
Published Mar 26, 2024
Tracked Since Feb 18, 2026