Record summary

CVE-2024-34257 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 13, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 1, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unknown

CVE List9.1.0cu.2112_b20220316affected

Nuclei templates

1
ProjectDiscoveryHIGHTOTOLINK EX1800T TOTOLINK EX1800T - Command Injection

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.

Impact

Unauthenticated attackers can execute arbitrary commands via the apcliEncrypType parameter, gaining device administrator privileges.

Remediation

Update TOTOLINK EX1800T firmware to a version that patches the command injection vulnerability.

Authorspussycat0x
Template tagscvecve2024rceunauthvkevvuln
Shodan: http.title:"totolink"
FOFA: title="totolink"
Google: intitle:"totolink"

Source: ProjectDiscovery

References

3