Record summary

CVE-2024-51228 has a selected CVSS score of 6.8 (medium); EIP currently links 1 Nuclei template.

Description

An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 29, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 29, 2024 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unknown

CVE List1.0.4-B20171106.1512affected

Default status: unknown

CVE List2.1.6-B20171121.1002affected

Default status: unknown

CVE List2.1.6-B20170724.1420affected
2.1.8-B20171113.1408affected
2.1.8-B20191010.1107affected

Default status: unknown

CVE List2.0.2-B20170511.1523affected

Nuclei templates

1
ProjectDiscoveryMEDIUMTOTOLINK CX-A3002RU - Remote Code ExecutionCVSS 6.8

An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.

Impact

Attackers can exploit this vulnerability to compromise system security and integrity.

Remediation

Apply the latest security patches and updates to address this vulnerability.

WeaknessesCWE-78
AuthorsDhiyaneshDK
Template tagscvecve2024totolinktime-based-sqlisqlivulnvkev
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Shodan: html:"TOTOLINK"

Source: ProjectDiscovery

References

6