CVE-2024-34257
TOTOLINK EX1800T apcliEncrypType Vulnerability
Record summary
CVE-2024-34257 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 13, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 1, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
EX1800TBrowse TOTOLINK / EX1800T | VulnCheck | Version data not supplied | |
ex1800t_firmwareBrowse totolink / ex1800t_firmwareDefault status: unknown | CVE List | 9.1.0cu.2112_b20220316 | affected |
Nuclei templates
1ProjectDiscoveryHIGHTOTOLINK EX1800T TOTOLINK EX1800T - Command Injection
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.
Impact
Unauthenticated attackers can execute arbitrary commands via the apcliEncrypType parameter, gaining device administrator privileges.
Remediation
Update TOTOLINK EX1800T firmware to a version that patches the command injection vulnerability.
Source: ProjectDiscovery